VDB

CVE-2026-22250

CVE-2026-22250 PUBLISHED CVSS 2.5 LOW

wlc is a Weblate command-line client using Weblate's REST API. Prior to 1.17.0, the SSL verification would be skipped for some crafted URLs. This vulnerability is fixed in 1.17.0.

EPSS 0.00% · 0.3th percentile

Risk Scores

CVSS 3.1
2.5
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:L/I:N/A:N
EPSS Score
0.00%
0.3th percentile

Affected Products

VendorProductVersions
PyPIwlc0, 0
weblatewlc0, 0
WeblateOrgwlc< 1.17.0, < 1.17.0

Timeline

  • Jan 7, 2026 Fix PR Merged
  • Jan 12, 2026 CVE Published
  • Jan 13, 2026 EPSS Score
  • Jan 16, 2026 EPSS Score
  • Jan 19, 2026 EPSS Score
  • Jan 22, 2026 EPSS Score
  • Jan 24, 2026 PoC Published
  • Jan 24, 2026 PoC Published
  • Jan 25, 2026 EPSS Score
  • Jan 28, 2026 EPSS Score
  • Jan 30, 2026 Security Advisory
  • Jan 31, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›