There are 3 open security issues in bookworm.
3 issues left for the package maintainer to handle:
- CVE-2026-22250:
(needs triaging)
wlc is a Weblate command-line client using Weblate's REST API. Prior to 1.17.0, the SSL verification would be skipped for some crafted URLs. This vulnerability is fixed in 1.17.0.
- CVE-2026-22251:
(needs triaging)
wlc is a Weblate command-line client using Weblate's REST API. Prior to 1.17.0, wlc supported providing unscoped API keys in the setting. This practice was discouraged for years, but the code was never removed. This might cause the API key to be leaked to different servers.
- CVE-2026-23535:
(needs triaging)
wlc is a Weblate command-line client using Weblate's REST API. Prior to 1.17.2, the multi-translation download could write to an arbitrary location when instructed by a crafted server. This vulnerability is fixed in 1.17.2.
You can find information about how to handle these issues in the security team's documentation.