The several endpoints could leak object existence information to users who had no access to it by HTTP status code 403 instead of 404.
Thanks to Yaohui Wang for reporting this via GitHub.
"https://github.com/pypa/advisory-database/blob/main/vulns/weblate/PYSEC-2026-3941.yaml"