CVE-2025-67492: 
Python vulnerability analysis and mitigation

Overview

CVE-2025-67492 is a vulnerability in Weblate, a web-based localization tool, where an over-permissive webhook endpoint allows unauthenticated attackers to trigger mass repository updates and enumerate components via a crafted webhook payload. It affects all Weblate versions prior to 5.15 and was disclosed on December 15, 2025. The vulnerability carries a CVSS v3.1 base score of 5.3 (Medium) (Github Advisory, Weblate Advisory).

Technical details

The root cause is classified as CWE-1286 (Improper Validation of Syntactic Correctness of Input): the webhook endpoint in weblate/trans/views/hooks.py did not validate that the full_name field in incoming webhook payloads was well-formed (i.e., contained a slash and met a minimum length) before using it in repository matching queries. An unauthenticated remote attacker could send a crafted HTTP POST request with a blank, too-short, or otherwise malformed full_name value, causing the endpoint to perform overly broad repository lookups and trigger updates across many repositories. The fix, merged in PR #17221, introduces a validate_full_name() function that enforces the presence of a slash and a minimum length before the value is used (Weblate Advisory, Fix PR).

Impact

Successful exploitation allows an unauthenticated attacker to trigger repository update operations across many or all repositories configured in a Weblate instance, potentially causing unintended synchronization activity and resource consumption. Additionally, the over-permissive behavior enables component enumeration, exposing information about the internal structure of the Weblate deployment (confidentiality impact: Low). Integrity and availability impacts are rated None in the CVSS scoring, though mass update triggering could indirectly affect operational stability (Github Advisory, Weblate Advisory).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The vulnerability requires no authentication, no user interaction, and is network-accessible, making it low-complexity to attempt. The EPSS score is approximately 0.019% (0.041% per Feedly), placing it in the 5th percentile for exploitation likelihood. It is not listed in the CISA Known Exploited Vulnerabilities catalog. The vulnerability was responsibly disclosed by Hector Ruiz Ruiz and NaxusAI (Github Advisory, Weblate Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing Weblate instances running versions prior to 5.15 using search engines (e.g., Shodan, Censys) or by checking the Weblate version disclosure on the login or about page.
  2. Locate the webhook endpoint: Weblate exposes a service hook endpoint (e.g., /hooks/github/, /hooks/gitlab/, /hooks/bitbucket/) that accepts POST requests from version control platforms.
  3. Craft a malicious payload: Construct a webhook payload (mimicking a GitHub, GitLab, or Bitbucket push event) with a blank, missing, or malformed full_name field (e.g., {"repository": {"full_name": ""}}).
  4. Send the request: Submit the crafted POST request to the Weblate webhook endpoint without any authentication credentials.
  5. Trigger mass repository updates: Due to the lack of full_name validation, the endpoint performs an overly broad repository match, triggering update operations across many or all configured repositories.
  6. Enumerate components: Observe response behavior or side effects (e.g., timing differences, error messages) to infer the existence and names of Weblate components (Weblate Advisory, Fix PR).

Indicators of compromise

  • Network: Unusual or high-volume POST requests to Weblate webhook endpoints (/hooks/github/, /hooks/gitlab/, /hooks/bitbucket/, /hooks/gitea/, etc.) from unexpected or unknown IP addresses; requests with minimal or malformed JSON payloads.
  • Logs: Weblate access logs showing repeated webhook POST requests with empty or short full_name values; abnormal spikes in repository update activity logged by Weblate.
  • Application Behavior: Unexpected or simultaneous repository update jobs triggered across many components in the Weblate task queue; increased background task activity without corresponding legitimate VCS push events.

Mitigation and workarounds

Upgrade Weblate to version 5.15 or later, which includes the fix that validates the full_name field in webhook payloads before use (PR #17221). As an immediate workaround for those unable to upgrade, disable webhooks entirely by setting ENABLE_HOOKS = False in the Weblate configuration. Additionally, restricting webhook endpoint access to trusted IP ranges (e.g., known VCS provider IP ranges) at the network or reverse proxy level can reduce exposure (Weblate Advisory, Fix PR).

Community reactions

The vulnerability was responsibly disclosed by Hector Ruiz Ruiz and NaxusAI, and the Weblate maintainer (nijel) published the advisory and merged the fix on December 15, 2025. The issue received routine coverage from vulnerability tracking services including CIRCL Vulnerability Lookup, CVEFeed, and VulDB, with no notable broader media coverage or significant community debate observed (Weblate Advisory).

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management