CVE-2026-22251: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-22251 is an insecure API key configuration vulnerability in wlc, the Weblate command-line client for Weblate's REST API. Prior to version 1.17.0, wlc allowed API keys to be specified in an unscoped manner (e.g., in the [weblate] section of the configuration file), rather than being bound to a specific server URL. This design flaw could cause the API key to be leaked to unintended servers. The vulnerability was disclosed on January 12, 2026, and affects all wlc versions before 1.17.0. It carries a CVSS v3.1 base score of 5.3 (Medium) per the CNA (GitHub), or 5.5 (Medium) per NVD (GitHub Advisory, Feedly).

Technical details

The root cause is classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor). Historically, wlc supported placing API keys in the [weblate] section or arbitrary configuration sections without binding them to a specific API URL. The get_url_key() method in wlc/config.py would read the key from the [weblate] section first, and only fall back to the URL-scoped [keys] section if no key was found there. This meant that if a user had an unscoped key configured, it could be sent to any server the client connected to — including unintended or malicious ones. The fix (PR #1098, commit aafdb50) refactored get_url_key() to exclusively read keys from the [keys] section using the API URL as the lookup key, and introduced cli_key/cli_url attributes for command-line overrides (GitHub Advisory, GitHub PR).

Impact

Successful exploitation could result in the disclosure of a user's Weblate API key to an unauthorized or malicious server, compromising confidentiality of authentication credentials. An attacker who obtains the leaked API key could use it to authenticate to the legitimate Weblate instance and perform actions on behalf of the victim, such as modifying translation projects or accessing sensitive project data. There is no integrity or availability impact directly from this vulnerability itself (GitHub Advisory).

Exploitability

No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported. The vulnerability requires local access, low privileges, and user interaction (per the CNA CVSS vector), making it relatively difficult to exploit opportunistically. The EPSS score is approximately 0.011% (0.000110), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The issue was responsibly reported via HackerOne by researcher 'wh1zee' (GitHub Advisory, Feedly).

Exploitation steps

  1. Identify a target: An attacker with local access to a system where wlc is installed and configured checks the user's wlc configuration file (e.g., ~/.config/weblate or weblate.ini) for an unscoped API key set in the [weblate] section.
  2. Manipulate the target URL: The attacker modifies or influences the url setting in the configuration (or uses a malicious project-level .weblate config file in a directory the victim uses) to point to an attacker-controlled server.
  3. Trigger wlc execution: The attacker waits for or induces the victim to run a wlc command (e.g., wlc list-projects) in a directory containing the malicious configuration.
  4. Capture the API key: Because the unscoped key is sent with all requests regardless of the target URL, the attacker's server receives the API key in the HTTP request's Authorization header.
  5. Abuse the captured key: The attacker uses the captured API key to authenticate to the legitimate Weblate instance and perform unauthorized actions (GitHub Advisory, GitHub PR).

Indicators of compromise

  • File System: Presence of an unscoped API key in the [weblate] section (e.g., key = <value>) of ~/.config/weblate, ~/.config/weblate.ini, or any project-level .weblate/weblate.ini file — rather than in the [keys] section keyed by URL.
  • Network: Outbound HTTP requests from wlc to unexpected or unknown API endpoints containing an Authorization header with a Weblate API key.
  • Logs: Weblate server access logs showing API authentication from unexpected IP addresses or user agents using a known API key.

Mitigation and workarounds

Upgrade wlc to version 1.17.0 or later, which enforces that API keys must be specified in the [keys] section of the configuration file, scoped to a specific API URL. As an immediate workaround without upgrading, remove any unscoped key = entries from the [weblate] section (or other non-[keys] sections) of the configuration file, and migrate keys to the [keys] section using the format <API_URL> = <KEY>. For example: [keys] https://hosted.weblate.org/api/ = APIKEY (GitHub Advisory, GitHub PR).

Community reactions

The vulnerability was reported to the Weblate team via HackerOne by researcher 'wh1zee' and was addressed promptly by maintainer 'nijel' in PR #1098, merged on January 7, 2026, ahead of the public disclosure on January 12, 2026. The fix was also accompanied by documentation updates to remove references to the deprecated key configuration pattern. No significant broader media coverage or notable community debate has been observed beyond standard vulnerability tracking (GitHub Advisory, GitHub PR).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

wlc

Affected

sid

wlc: 1.17.2-1

Fixed

trixie

wlc

Affected

Ubuntu

Fixed

bionic (esm-apps)

wlc: 0.8-1ubuntu0.1~esm1

Fixed

devel

wlc

Affected

focal (esm-apps)

wlc: 1.2-1ubuntu0.20.04.1~esm1

Fixed

jammy

wlc

Affected

jammy (esm-apps)

wlc: 1.2-1ubuntu0.22.04.1~esm1

Fixed

noble

wlc

Affected

noble (esm-apps)

wlc: 1.13-2ubuntu0.1~esm1

Fixed

questing

wlc: 1.15-2ubuntu0.1

Fixed

Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management