CVE-2025-58352

Weblate is a web based localization tool. Versions lower than 5.13.1 contain a vulnerability that causes long session expiry during the second factor verification. The long session expiry could be used to circumvent rate limiting of the second factor. This issue is fixed in version 5.13.1.
Configurations

Configuration 1 (hide)

cpe:2.3:a:weblate:weblate:*:*:*:*:*:*:*:*

History

18 Sep 2025, 16:25

Type Values Removed Values Added
References () https://github.com/WeblateOrg/weblate/commit/0b46fe596231dd456283ead66699ae5516f23908 - () https://github.com/WeblateOrg/weblate/commit/0b46fe596231dd456283ead66699ae5516f23908 - Patch
References () https://github.com/WeblateOrg/weblate/pull/16002 - () https://github.com/WeblateOrg/weblate/pull/16002 - Issue Tracking
References () https://github.com/WeblateOrg/weblate/security/advisories/GHSA-377j-wj38-4728 - () https://github.com/WeblateOrg/weblate/security/advisories/GHSA-377j-wj38-4728 - Vendor Advisory
First Time Weblate weblate
Weblate
CPE cpe:2.3:a:weblate:weblate:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5

05 Sep 2025, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-05 00:15

Updated : 2025-09-18 16:25


NVD link : CVE-2025-58352

Mitre link : CVE-2025-58352

CVE.ORG link : CVE-2025-58352


JSON object : View

Products Affected

weblate

  • weblate
CWE
CWE-613

Insufficient Session Expiration