CVE-2025-58352 Details
Description
Weblate is a web based localization tool. Versions lower than 5.13.1 contain a vulnerability that causes long session expiry during the second factor verification. The long session expiry could be used to circumvent rate limiting of the second factor. This issue is fixed in version 5.13.1.
A vulnerability exists in Weblate versions prior to 5.13.1, where the session expiry during second-factor verification is excessively long. This prolonged expiry can be exploited to bypass rate limiting on the second factor, potentially leading to abuse of the authentication process.
Users can upgrade to Weblate version 5.13.1 to address this vulnerability. Instructions for updating can be found in the Weblate documentation.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Sep 5, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-613 | Insufficient Session Expiration | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| weblate weblate | < 5.13.1 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Sep 18, 2025 | Initial Analysis | [email protected] |
| Sep 5, 2025 | New CVE Received | [email protected] |