CVE-2025-58352

Weblate is a web based localization tool. Versions lower than 5.13.1 contain a vulnerability that causes long session expiry during the second factor verification. The long session expiry could be used to circumvent rate limiting of the second factor. This issue is fixed in version 5.13.1.
Configurations

Configuration 1 (hide)

cpe:2.3:a:weblate:weblate:*:*:*:*:*:*:*:*

History

18 Sep 2025, 16:25

Type Values Removed Values Added
First Time Weblate
Weblate weblate
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CPE cpe:2.3:a:weblate:weblate:*:*:*:*:*:*:*:*
References () https://github.com/WeblateOrg/weblate/commit/0b46fe596231dd456283ead66699ae5516f23908 - () https://github.com/WeblateOrg/weblate/commit/0b46fe596231dd456283ead66699ae5516f23908 - Patch
References () https://github.com/WeblateOrg/weblate/pull/16002 - () https://github.com/WeblateOrg/weblate/pull/16002 - Issue Tracking
References () https://github.com/WeblateOrg/weblate/security/advisories/GHSA-377j-wj38-4728 - () https://github.com/WeblateOrg/weblate/security/advisories/GHSA-377j-wj38-4728 - Vendor Advisory

05 Sep 2025, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-05 00:15

Updated : 2025-09-18 16:25


NVD link : CVE-2025-58352

Mitre link : CVE-2025-58352

CVE.ORG link : CVE-2025-58352


JSON object : View

Products Affected

weblate

  • weblate
CWE
CWE-613

Insufficient Session Expiration