Exposure of personal IP address via Email

Program: Weblate Bug Type: PII Exposure Bounty: Unspecified Date: 2025-07-16
PII-Exposure privacy-violation sensitive-data

Summary

Weblate is an opensource translation integration software that translates documentations, and various commuication. When Weblate sends an email for various reasons such as notifications, password reset, etc. They include the Public IP address of the user doing the action. This passes through many smtp servers in the middle, storing information. Violating GDPR as Public IP is a PII. Impact is that exposed IP can be used for various attcks and recon.

References