CVE-2026-22250: Weblate Wlc

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

wlc is a Weblate command-line client using Weblate's REST API. Prior to 1.17.0, the SSL verification would be skipped for some crafted URLs. This vulnerability is fixed in 1.17.0.

Affected products

  • Weblate Wlc: before 1.17.0 (fixed in 1.17.0)

Published 2026-01-12. Last modified 2026-06-17.