Количество 3
Количество 3
CVE-2026-41519
Weblate is a web based localization tool. Prior to version 5.17.1, when a user changes their password, browser sessions are correctly invalidated via "cycle_session_keys()", but DRF API tokens ("wlu_*" prefix) stored in "authtoken_token" are not revoked. This issue has been patched in version 5.17.1.
CVE-2026-41519
Weblate is a web based localization tool. Prior to version 5.17.1, whe ...
GHSA-6j8j-4qp3-36p2
Weblate Doesn't Invalidate API Token on Password Change
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-41519 Weblate is a web based localization tool. Prior to version 5.17.1, when a user changes their password, browser sessions are correctly invalidated via "cycle_session_keys()", but DRF API tokens ("wlu_*" prefix) stored in "authtoken_token" are not revoked. This issue has been patched in version 5.17.1. | CVSS3: 4.2 | 0% Низкий | 3 месяца назад | |
CVE-2026-41519 Weblate is a web based localization tool. Prior to version 5.17.1, whe ... | CVSS3: 4.2 | 0% Низкий | 3 месяца назад | |
GHSA-6j8j-4qp3-36p2 Weblate Doesn't Invalidate API Token on Password Change | CVSS3: 4.2 | 0% Низкий | 4 месяца назад |
Уязвимостей на страницу