All vulnerabilities

CVE-2026-55227

PyPI · weblate

Summary

Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups

Advisory details

Impact

The several endpoints could leak object existence information to users who had no access to it by HTTP status code 403 instead of 404.

Patches

References

Thanks to Yaohui Wang for reporting this via GitHub.

References