
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-22250 is an improper certificate validation vulnerability in wlc, the Weblate command-line client that interfaces with Weblate's REST API via Python. Prior to version 1.17.0, SSL verification was incorrectly skipped for certain crafted URLs due to a flawed hostname-matching logic. The vulnerability was disclosed on January 12, 2026, and affects all wlc versions before 1.17.0. The CNA (GitHub) assigned a CVSS v3.1 score of 2.5 (Low), while NVD assessed it at 5.5 (Medium) (GitHub Advisory).
The root cause is CWE-295 (Improper Certificate Validation). The vulnerable code in wlc/__init__.py used Python's str.startswith() to check if a URL's network location began with "127.0.0.1" to determine whether to skip SSL verification — a logic intended for localhost connections. This meant any hostname beginning with "127.0.0.1" (e.g., 127.0.0.1.attacker.com) would incorrectly be treated as localhost, causing SSL certificate verification to be bypassed for that HTTPS connection. The fix, merged in PR #1097, replaced the prefix-based check with an exact set membership lookup against {"127.0.0.1", "localhost", "::1", "[::1]"} using url.hostname (GitHub PR #1097, Patch Commit). Exploitation requires local access, low privileges, and user interaction (e.g., a user being tricked into using a malicious wlc configuration file pointing to a crafted URL) (GitHub Advisory).
Successful exploitation allows an attacker to intercept or manipulate HTTPS communications between the wlc client and a Weblate server by bypassing SSL certificate validation, enabling a man-in-the-middle (MitM) attack. The primary risk is to confidentiality of API tokens or session data transmitted over the connection, and potentially to integrity if responses are tampered with. The impact is limited in scope — it requires local access and user interaction, and does not directly affect availability (GitHub Advisory).
No public exploit code or in-the-wild exploitation has been reported for this vulnerability. The EPSS score is extremely low at 0.0001, and it is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The vulnerability was reported to the Weblate project via HackerOne by researcher Zee99y (GitHub Advisory). Exploitation is constrained by the requirement for local access, low privileges, and user interaction, making opportunistic mass exploitation unlikely.
.weblate) that sets the Weblate API URL to a crafted HTTPS URL whose hostname starts with 127.0.0.1 but resolves to an attacker-controlled server (e.g., https://127.0.0.1.attacker.com/api/)..weblate or .weblate.ini).wlc command (e.g., wlc list-projects), the client connects to the attacker's server without verifying the SSL certificate, because the hostname starts with 127.0.0.1 and bypasses the SSL check.Authorization header) and can return forged responses, enabling credential theft or data manipulation (GitHub PR #1097, GitHub Advisory).127.0.0.1 (e.g., 127.0.0.1.example.com) on port 443; TLS handshakes where the server certificate does not match the expected Weblate server..weblate, .weblate.ini, weblate.ini) in project directories or ~/.config/weblate containing unfamiliar API URLs.127.0.0.1 that are not the local loopback address; absence of SSL verification errors where they would be expected for non-localhost HTTPS endpoints.Upgrade wlc to version 1.17.0 or later, which replaces the flawed startswith-based localhost detection with exact hostname matching (GitHub Advisory, Patch Commit). Install the patched version via pip: pip3 install --upgrade wlc. As a workaround prior to patching, avoid using untrusted wlc configuration files, as a malicious configuration pointing to a crafted URL is the primary attack vector (GitHub Advisory).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."