CVE-2026-55227: Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups
The several endpoints could leak object existence information to users who had no access to it by HTTP status code 403 instead of 404.
References
- github.com/WeblateOrg/weblate/commit/836bc082803d49d02f2831ec8339268eb66bcdae
- github.com/WeblateOrg/weblate/pull/19971
- github.com/WeblateOrg/weblate/releases/tag/weblate-2026.7
- github.com/WeblateOrg/weblate/security/advisories/GHSA-2p9g-x3cv-5hh4
- github.com/advisories/GHSA-2p9g-x3cv-5hh4
- nvd.nist.gov/vuln/detail/CVE-2026-55227
Code Behaviors & Features
Detect and mitigate CVE-2026-55227 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →