Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-9rp8-h4g8-8766 | Weblate wlc has insecure API key configuration |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 12 Jan 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 12 Jan 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | wlc is a Weblate command-line client using Weblate's REST API. Prior to 1.17.0, wlc supported providing unscoped API keys in the setting. This practice was discouraged for years, but the code was never removed. This might cause the API key to be leaked to different servers. | |
| Title | wlc may leak API keys due to an insecure API key configuration | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-01-12T18:43:53.664Z
Reserved: 2026-01-07T05:19:12.921Z
Link: CVE-2026-22251
Updated: 2026-01-12T18:43:24.564Z
Status : Received
Published: 2026-01-12T18:15:49.457
Modified: 2026-01-12T18:15:49.457
Link: CVE-2026-22251
No data.
OpenCVE Enrichment
No data.
Github GHSA