Weblate lacks rate limiting when verifying second factor
Moderate severity
GitHub Reviewed
Published
Jun 16, 2025
in
WeblateOrg/weblate
•
Updated Jun 17, 2025
Description
Published to the GitHub Advisory Database
Jun 16, 2025
Reviewed
Jun 16, 2025
Published by the National Vulnerability Database
Jun 16, 2025
Last updated
Jun 17, 2025
Impact
The verification of the second factor was not subject to rate limiting. The absence of rate limiting on the second factor endpoint allows an attacker with valid credentials to automate OTP guessing.
Patches
This issue has been addressed in Weblate 5.12 via WeblateOrg/weblate#14918.
References
Thanks to obscuredeer for reporting this issue at HackerOne.
References