DEBIAN-CVE-2026-22251

Source
https://security-tracker.debian.org/tracker/CVE-2026-22251
Import Source
https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-22251.json
JSON Data
https://api.test.osv.dev/v1/vulns/DEBIAN-CVE-2026-22251
Upstream
Published
2026-01-12T18:15:49.457Z
Modified
2026-01-28T09:16:23.890617Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

wlc is a Weblate command-line client using Weblate's REST API. Prior to 1.17.0, wlc supported providing unscoped API keys in the setting. This practice was discouraged for years, but the code was never removed. This might cause the API key to be leaked to different servers.

References

Affected packages

Debian:11 / wlc

Package

Name
wlc
Purl
pkg:deb/debian/wlc?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.2-1
1.2-2
1.13-1
1.13-2
1.14-1
1.15-1
1.15-2
1.16.1-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source

"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-22251.json"

Debian:12 / wlc

Package

Name
wlc
Purl
pkg:deb/debian/wlc?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.13-2
1.14-1
1.15-1
1.15-2
1.16.1-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source

"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-22251.json"

Debian:13 / wlc

Package

Name
wlc
Purl
pkg:deb/debian/wlc?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.15-1
1.15-2
1.16.1-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source

"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-22251.json"

Debian:14 / wlc

Package

Name
wlc
Purl
pkg:deb/debian/wlc?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.15-1
1.15-2
1.16.1-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source

"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-22251.json"