Launch Week Day 1: Announcing Security Design Review
MEDIUM 4.2 PyPI

Weblate Doesn't Invalidate API Token on Password Change

GHSA-6j8j-4qp3-36p2 · CVE-2026-41519

Published · Modified

Description

Impact

When a user changes their password, browser sessions are correctly invalidated via cycle_session_keys(), but DRF API tokens (wlu_* prefix) stored in authtoken_token are not revoked.

Patches

Resources

Weblate thanks Sang Yu Jeon for reporting this via GitHub.

Ready to move

Start Securing

Free, no credit card | First findings in minutes