CVE-2025-58352: Weblate has long session expiry times during second factor verification
Impact The verification of the second factor had too long a session expiry. The long session expiry could be used to circumvent rate limiting of the second factor.
Patches This issue has been addressed in Weblate 5.13.1 via https://github.com/WeblateOrg/weblate/pull/16002.
References Thanks to Nahid Hasan Limon for reporting this issue responsibly.
Other sources
Weblate is a web based localization tool. Versions lower than 5.13.1 contain a vulnerability that causes long session expiry during the second factor verification. The long session expiry could be used to circumvent rate limiting of the second factor. This issue is fixed in version 5.13.1.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-58352?
CVE-2025-58352 has a high severity due to its potential to bypass rate limiting on second factor authentication.
How do I fix CVE-2025-58352?
To fix CVE-2025-58352, upgrade to Weblate version 5.13.1 or later.
What is the impact of CVE-2025-58352?
The impact of CVE-2025-58352 allows attackers to exploit a long session expiry to circumvent rate limiting for two-factor authentication.
Which versions of Weblate are affected by CVE-2025-58352?
Weblate versions prior to 5.13.1 are affected by CVE-2025-58352.
What is the nature of the vulnerability in CVE-2025-58352?
The vulnerability in CVE-2025-58352 relates to insufficient control over session expiry for the second factor in authentication.