LOW 2.5 PyPI

Weblate command-line client susceptible to SSL verification skip

GHSA-2mmv-7rrp-g8xh · CVE-2026-22250 · PYSEC-2026-2051

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Impact

The SSL verification would be skipped for some crafted URLs.

Patches

Workarounds

Avoid using untrusted wlc configurations, as that might cause insecure connections.

References

This issue was reported to us by wh1zee via HackerOne.

Ready to move

Start Securing

Free, no credit card | First findings in minutes