{"id":"CVE-2026-22250","aliases":["GHSA-2mmv-7rrp-g8xh","PYSEC-2026-2051"],"url":"https://o3.security/vulnerability/CVE-2026-22250","summary":"wlc can skip SSL verification","details":"wlc is a Weblate command-line client using Weblate's REST API. Prior to 1.17.0, the SSL verification would be skipped for some crafted URLs. This vulnerability is fixed in 1.17.0.","published":"2026-01-12T17:52:01.390Z","modified":"2026-07-15T01:49:17.771142176Z","cvss":{"score":2.5,"severity":"LOW","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:L/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"wlc","fixedVersion":"1.17.0"}],"fix":{"url":"https://github.com/WeblateOrg/wlc/commit/a513864ec4daad00146e6d6e039559726e256fa3","label":"WeblateOrg/wlc@a513864"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/22xxx/CVE-2026-22250.json"},{"type":"ADVISORY","url":"https://github.com/WeblateOrg/wlc/security/advisories/GHSA-2mmv-7rrp-g8xh"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-22250"},{"type":"FIX","url":"https://github.com/WeblateOrg/wlc/commit/a513864ec4daad00146e6d6e039559726e256fa3"},{"type":"FIX","url":"https://github.com/WeblateOrg/wlc/pull/1097"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:49:17.771142176Z"}}