THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-2p9g-x3cv-5hh4 (medium) — Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups

[GHSA] GHSA-2p9g-x3cv-5hh4 (medium) — Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups

medgithub_advisoriesPublished 2026-08-28

GHSA-2p9g-x3cv-5hh4 Severity: medium CVE: CVE-2026-55227

Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups

### Impact The several endpoints could leak object existence information to users who had no access to it by HTTP status code 403 instead of 404.

### Patches * https://github.com/WeblateOrg/weblate/pull/19971

### References Th

Indicators of compromise

Original source: https://github.com/advisories/GHSA-2p9g-x3cv-5hh4