Launch Week Day 1: Announcing Security Design Review
MEDIUM 5.0 PyPI

Weblate: Authenticated SSRF via redirect bypass of ALLOWED_ASSET_DOMAINS in screenshot URL uploads

GHSA-5fhx-9jwj-867m · CVE-2026-33440

Published · Modified

Description

Impact

The ALLOWED_ASSET_DOMAINS setting applied only to the first issued requests and didn't restrict possible redirects.

Patches

References

This issue was reported by @spbavarva via GitHub.

Ready to move

Start Securing

Free, no credit card | First findings in minutes