PT-2025-25575 · Weblate · Weblate

·

CVE-2025-49134

·

Published

2025-06-16

·

Updated

2026-07-07

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Weblate versions prior to 5.12
Description The issue concerns the inclusion of the full IP address of the acting user in audit log notifications. This information could be obtained by third-party servers, such as SMTP relays or spam filters.
Recommendations For versions prior to 5.12, update to version 5.12 to resolve the issue. As a temporary workaround, consider restricting access to audit log notifications to minimize the risk of IP address exposure.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-49134
GHSA-4QQF-9M5C-W2C5
PYSEC-2026-2038

Affected Products

Weblate