PT-2026-82301 · Weblate · Weblate
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Weblate versions prior to 2026.7
Description
A user with the "Edit source" role can cause a denial of service by storing a malicious regular expression in a source string's flags. Regular expressions provided via the regex quality check and regex placeholders are compiled during validation but executed within
RegexCheck and PlaceholderCheck without a timeout. This allows a catastrophic-backtracking pattern—a regular expression that takes an exponential amount of time to process certain strings—to consume CPU resources indefinitely. Since these checks are re-run for every linked target unit when source unit flags change, a single edit can lead to a sustained CPU-bound denial of service.Recommendations
Update to version 2026.7.
Exploit
Fix
DoS
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Weblate