CVE-2026-22250: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-22250 is an improper certificate validation vulnerability in wlc, the Weblate command-line client that interfaces with Weblate's REST API via Python. Prior to version 1.17.0, SSL verification was incorrectly skipped for certain crafted URLs due to a flawed hostname-matching logic. The vulnerability was disclosed on January 12, 2026, and affects all wlc versions before 1.17.0. The CNA (GitHub) assigned a CVSS v3.1 score of 2.5 (Low), while NVD assessed it at 5.5 (Medium) (GitHub Advisory).

Technical details

The root cause is CWE-295 (Improper Certificate Validation). The vulnerable code in wlc/__init__.py used Python's str.startswith() to check if a URL's network location began with "127.0.0.1" to determine whether to skip SSL verification — a logic intended for localhost connections. This meant any hostname beginning with "127.0.0.1" (e.g., 127.0.0.1.attacker.com) would incorrectly be treated as localhost, causing SSL certificate verification to be bypassed for that HTTPS connection. The fix, merged in PR #1097, replaced the prefix-based check with an exact set membership lookup against {"127.0.0.1", "localhost", "::1", "[::1]"} using url.hostname (GitHub PR #1097, Patch Commit). Exploitation requires local access, low privileges, and user interaction (e.g., a user being tricked into using a malicious wlc configuration file pointing to a crafted URL) (GitHub Advisory).

Impact

Successful exploitation allows an attacker to intercept or manipulate HTTPS communications between the wlc client and a Weblate server by bypassing SSL certificate validation, enabling a man-in-the-middle (MitM) attack. The primary risk is to confidentiality of API tokens or session data transmitted over the connection, and potentially to integrity if responses are tampered with. The impact is limited in scope — it requires local access and user interaction, and does not directly affect availability (GitHub Advisory).

Exploitability

No public exploit code or in-the-wild exploitation has been reported for this vulnerability. The EPSS score is extremely low at 0.0001, and it is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The vulnerability was reported to the Weblate project via HackerOne by researcher Zee99y (GitHub Advisory). Exploitation is constrained by the requirement for local access, low privileges, and user interaction, making opportunistic mass exploitation unlikely.

Exploitation steps

  1. Craft a malicious wlc configuration: Create a wlc configuration file (e.g., .weblate) that sets the Weblate API URL to a crafted HTTPS URL whose hostname starts with 127.0.0.1 but resolves to an attacker-controlled server (e.g., https://127.0.0.1.attacker.com/api/).
  2. Social engineering / local access: Convince the target user to use this malicious configuration file, or place it in a directory where wlc will auto-discover it (e.g., the project root as .weblate or .weblate.ini).
  3. Position for MitM: Set up an attacker-controlled HTTPS server at the crafted domain with a self-signed or rogue TLS certificate.
  4. Trigger wlc execution: When the victim runs any wlc command (e.g., wlc list-projects), the client connects to the attacker's server without verifying the SSL certificate, because the hostname starts with 127.0.0.1 and bypasses the SSL check.
  5. Intercept credentials/data: The attacker's server receives the victim's Weblate API key (sent in the Authorization header) and can return forged responses, enabling credential theft or data manipulation (GitHub PR #1097, GitHub Advisory).

Indicators of compromise

  • Network: Outbound HTTPS connections from the wlc client to unexpected hostnames that begin with 127.0.0.1 (e.g., 127.0.0.1.example.com) on port 443; TLS handshakes where the server certificate does not match the expected Weblate server.
  • File System: Presence of unexpected or modified wlc configuration files (.weblate, .weblate.ini, weblate.ini) in project directories or ~/.config/weblate containing unfamiliar API URLs.
  • Logs: wlc command execution logs showing API requests to URLs with hostnames starting with 127.0.0.1 that are not the local loopback address; absence of SSL verification errors where they would be expected for non-localhost HTTPS endpoints.

Mitigation and workarounds

Upgrade wlc to version 1.17.0 or later, which replaces the flawed startswith-based localhost detection with exact hostname matching (GitHub Advisory, Patch Commit). Install the patched version via pip: pip3 install --upgrade wlc. As a workaround prior to patching, avoid using untrusted wlc configuration files, as a malicious configuration pointing to a crafted URL is the primary attack vector (GitHub Advisory).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

wlc

Affected

sid

wlc: 1.17.2-1

Fixed

trixie

wlc

Affected

Ubuntu

Fixed

bionic (esm-apps)

wlc: 0.8-1ubuntu0.1~esm1

Fixed

devel

wlc

Affected

focal (esm-apps)

wlc: 1.2-1ubuntu0.20.04.1~esm1

Fixed

jammy

wlc

Affected

jammy (esm-apps)

wlc: 1.2-1ubuntu0.22.04.1~esm1

Fixed

noble

wlc

Affected

noble (esm-apps)

wlc: 1.13-2ubuntu0.1~esm1

Fixed

questing

wlc: 1.15-2ubuntu0.1

Fixed

Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management