Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups
Moderate severity
GitHub Reviewed
Published
Jul 11, 2026
in
WeblateOrg/weblate
•
Updated Aug 28, 2026
Description
Published by the National Vulnerability Database
Aug 26, 2026
Published to the GitHub Advisory Database
Aug 28, 2026
Reviewed
Aug 28, 2026
Last updated
Aug 28, 2026
Impact
The several endpoints could leak object existence information to users who had no access to it by HTTP status code 403 instead of 404.
Patches
References
Thanks to Yaohui Wang for reporting this via GitHub.
References