CVE-2026-22250: Weblate Wlc
Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.
wlc is a Weblate command-line client using Weblate's REST API. Prior to 1.17.0, the SSL verification would be skipped for some crafted URLs. This vulnerability is fixed in 1.17.0.
Affected products
- Weblate Wlc: before 1.17.0 (fixed in 1.17.0)
Published 2026-01-12. Last modified 2026-06-17.