{"id":"CVE-2025-58352","aliases":["GHSA-377j-wj38-4728","PYSEC-2026-2036"],"title":"Weblate has a long session expiry when verifying second factor","summary":"Weblate has a long session expiry when verifying second factor","severity":"low","vendor":"weblate","product":"weblate","ecosystem":"pip","affected":["weblate < 5.13.1"],"patched":["weblate 5.13.1"],"published":"2025-09-04","updated":"2026-09-10","sourceUpdated":"2026-09-10T03:50:27.862938527Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-377j-wj38-4728","references":[{"url":"https://github.com/WeblateOrg/weblate/security/advisories/GHSA-377j-wj38-4728"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-58352"},{"url":"https://github.com/WeblateOrg/weblate/pull/16002"},{"url":"https://github.com/WeblateOrg/weblate/commit/0b46fe596231dd456283ead66699ae5516f23908"},{"url":"https://github.com/WeblateOrg/weblate"}],"tags":["osv","pip"],"epss":0.00283,"epssPercentile":0.21102,"ingestedAt":"2026-07-08T18:25:44.860Z","slug":"CVE-2025-58352","body":"## Overview\n\n### Impact\nThe verification of the second factor had too long a session expiry. The long session expiry could be used to circumvent rate limiting of the second factor.\n\n\n### Patches\nThis issue has been addressed in Weblate 5.13.1 via https://github.com/WeblateOrg/weblate/pull/16002.\n\n### References\nThanks to Nahid Hasan Limon for reporting this issue responsibly.\n\n## Affected packages\n\n- `weblate < 5.13.1`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `weblate 5.13.1`","depth":"sunlit","depthScore":14,"depthScoreParts":{"impact":13.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}