PT-2026-82301 · Weblate · Weblate

·

CVE-2026-62326

·

Published

2026-08-26

·

Updated

2026-08-26

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Weblate versions prior to 2026.7
Description A user with the "Edit source" role can cause a denial of service by storing a malicious regular expression in a source string's flags. Regular expressions provided via the regex quality check and regex placeholders are compiled during validation but executed within RegexCheck and PlaceholderCheck without a timeout. This allows a catastrophic-backtracking pattern—a regular expression that takes an exponential amount of time to process certain strings—to consume CPU resources indefinitely. Since these checks are re-run for every linked target unit when source unit flags change, a single edit can lead to a sustained CPU-bound denial of service.
Recommendations Update to version 2026.7.

Exploit

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-62326
GHSA-R52J-4VJP-Q949

Affected Products

Weblate