---
id: CVE-2025-58352
aliases:
  - GHSA-377j-wj38-4728
  - PYSEC-2026-2036
title: Weblate has a long session expiry when verifying second factor
summary: Weblate has a long session expiry when verifying second factor
severity: low
vendor: weblate
product: weblate
ecosystem: pip
affected:
  - weblate < 5.13.1
patched:
  - weblate 5.13.1
published: '2025-09-04'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T03:50:27.862938527Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-377j-wj38-4728'
references:
  - url: >-
      https://github.com/WeblateOrg/weblate/security/advisories/GHSA-377j-wj38-4728
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2025-58352'
  - url: 'https://github.com/WeblateOrg/weblate/pull/16002'
  - url: >-
      https://github.com/WeblateOrg/weblate/commit/0b46fe596231dd456283ead66699ae5516f23908
  - url: 'https://github.com/WeblateOrg/weblate'
tags:
  - osv
  - pip
epss: 0.00283
epssPercentile: 0.21109
ingestedAt: '2026-07-08T18:25:44.860Z'
---

## Overview

### Impact
The verification of the second factor had too long a session expiry. The long session expiry could be used to circumvent rate limiting of the second factor.


### Patches
This issue has been addressed in Weblate 5.13.1 via https://github.com/WeblateOrg/weblate/pull/16002.

### References
Thanks to Nahid Hasan Limon for reporting this issue responsibly.

## Affected packages

- `weblate < 5.13.1`

## Remediation

Upgrade to a patched release:

- `weblate 5.13.1`
