UNKNOWN PyPI
Weblate has a long session expiry when verifying second factor
GHSA-377j-wj38-4728 · CVE-2025-58352
Published · Modified
Description
Impact
The verification of the second factor had too long a session expiry. The long session expiry could be used to circumvent rate limiting of the second factor.
Patches
This issue has been addressed in Weblate 5.13.1 via https://github.com/WeblateOrg/weblate/pull/16002.
References
Thanks to Nahid Hasan Limon for reporting this issue responsibly.
References
- WEB https://github.com/WeblateOrg/weblate/security/advisories/GHSA-377j-wj38-4728
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2025-58352
- WEB https://github.com/WeblateOrg/weblate/pull/16002
- WEB https://github.com/WeblateOrg/weblate/commit/0b46fe596231dd456283ead66699ae5516f23908
- PACKAGE https://github.com/WeblateOrg/weblate
Ready to move
Start Securing
Free, no credit card | First findings in minutes