{"id":"CVE-2026-22250","aliases":["GHSA-2mmv-7rrp-g8xh","PYSEC-2026-2051"],"url":"https://o3.security/vulnerability/CVE-2026-22250","summary":"wlc can skip SSL verification","details":"### Impact\nThe SSL verification would be skipped for some crafted URLs.\n\n### Patches\n* https://github.com/WeblateOrg/wlc/pull/1097\n\n### Workarounds\nAvoid using untrusted wlc configurations, as that might cause insecure connections.\n\n### References\nThis issue was reported to us by [wh1zee](https://hackerone.com/wh1zee) via HackerOne.","published":"2026-01-12T17:52:01.390Z","modified":"2026-08-12T03:51:38.786032428Z","cvss":{"score":2.5,"severity":"LOW","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:L/I:N/A:N"},"epss":{"score":0.00139,"percentile":0.03493,"asOf":"2026-08-24"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"wlc","fixedVersion":"1.17.0"}],"fix":{"url":"https://github.com/WeblateOrg/wlc/commit/a513864ec4daad00146e6d6e039559726e256fa3","label":"WeblateOrg/wlc@a513864"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/22xxx/CVE-2026-22250.json"},{"type":"ADVISORY","url":"https://github.com/WeblateOrg/wlc/security/advisories/GHSA-2mmv-7rrp-g8xh"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-22250"},{"type":"FIX","url":"https://github.com/WeblateOrg/wlc/commit/a513864ec4daad00146e6d6e039559726e256fa3"},{"type":"FIX","url":"https://github.com/WeblateOrg/wlc/pull/1097"},{"type":"PACKAGE","url":"https://github.com/WeblateOrg/wlc"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:38.786032428Z"}}