Search
Find a vulnerability
Search criteria
9 vulnerabilities by allauth
CVE-2026-97764 (GCVE-0-2026-97764)
Vulnerability from nvd – Published: 2026-09-25 04:25 – Updated: 2026-09-25 13:37
VLAI
EPSS
VEX
Summary
django-allauth before 65.19.4 does not have the expected limits on failed login attempts because, in some common configurations, an attacker can leverage the handling of diacritics (e.g., accents) for a higher effective limit.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-25 13:37 UTC
CWE
- CWE-180 - Incorrect Behavior Order: Validate Before Canonicalize
Assigner
References
5 references
| URL | Tags |
|---|---|
| https://docs.allauth.org/en/latest/release-notes/… | release-notes |
| https://pypi.org/project/django-allauth/ | product |
| https://codeberg.org/allauth/django-allauth/commi… | patch |
| https://codeberg.org/allauth/django-allauth/commi… | patch |
| https://codeberg.org/allauth/django-allauth/commi… | technical-descriptionrelated |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| allauth | django-allauth |
Affected:
0.25.0 , < 65.19.4
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-97764",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-25T13:37:23.042548Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-25T13:37:50.367Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"collectionURL": "https://pypi.org",
"defaultStatus": "unaffected",
"modules": [
"allauth.account.utils",
"allauth.account.adapter.DefaultAccountAdapter"
],
"packageName": "django-allauth",
"packageURL": "pkg:pypi/django-allauth",
"product": "django-allauth",
"programFiles": [
"allauth/account/utils.py",
"allauth/account/adapter.py"
],
"programRoutines": [
{
"name": "allauth.account.utils.filter_users_by_username()"
},
{
"name": "allauth.account.utils.filter_users_by_email()"
},
{
"name": "allauth.account.utils._unicode_ci_compare()"
},
{
"name": "allauth.account.adapter.DefaultAccountAdapter._get_login_attempts_cache_key()"
}
],
"repo": "https://codeberg.org/allauth/django-allauth",
"vendor": "allauth",
"versions": [
{
"lessThan": "65.19.4",
"status": "affected",
"version": "0.25.0",
"versionType": "custom"
}
]
}
],
"configurations": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "1. Any of the following settings is enabled in Django configuration.\u003cbr\u003e \u003cbr\u003e\u003cspan style=\"background-color: rgb(255, 255, 255)\"\u003e65.4\u0026nbsp;\u003c/span\u003e\u003cspan style=\"background-color: rgb(255, 255, 255)\"\u003eand later:\u003cbr\u003e\u003c/span\u003eACCOUNT_LOGIN_METHODS = {\"username\", \"email\"}\u003cbr\u003eACCOUNT_LOGIN_METHODS = {\"username\"}\u003cbr\u003e\u003cspan style=\"background-color: rgb(255, 255, 255)\"\u003e\u003cbr\u003e65.3 and earlier:\u003c/span\u003e\u003cbr\u003e\u003cspan style=\"background-color: rgb(255, 255, 255)\"\u003e\u003cspan style=\"background-color: rgb(255, 255, 255)\"\u003eACCOUNT_AUTHENTICATION_METHOD = \"username_email\"\u003c/span\u003e\u003cbr\u003eACCOUNT_AUTHENTICATION_METHOD = \"username\"\u003cbr\u003e\u003cbr\u003e\u003c/span\u003e2. The username column in the database uses a collation such as utf8mb4_general_ci or utf8mb4_unicode_ci.\u003cbr\u003e\u003cbr\u003e"
}
],
"value": "1. Any of the following settings is enabled in Django configuration.\n \n65.4\u00a0and later:\nACCOUNT_LOGIN_METHODS = {\"username\", \"email\"}\nACCOUNT_LOGIN_METHODS = {\"username\"}\n\n65.3 and earlier:\nACCOUNT_AUTHENTICATION_METHOD = \"username_email\"\nACCOUNT_AUTHENTICATION_METHOD = \"username\"\n\n2. The username column in the database uses a collation such as utf8mb4_general_ci or utf8mb4_unicode_ci."
}
],
"descriptions": [
{
"lang": "en",
"value": "django-allauth before 65.19.4 does not have the expected limits on failed login attempts because, in some common configurations, an attacker can leverage the handling of diacritics (e.g., accents) for a higher effective limit."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 3.7,
"baseSeverity": "LOW",
"confidentialityImpact": "NONE",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-180",
"description": "CWE-180 Incorrect Behavior Order: Validate Before Canonicalize",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-25T04:25:57.932Z",
"orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"shortName": "mitre"
},
"references": [
{
"tags": [
"release-notes"
],
"url": "https://docs.allauth.org/en/latest/release-notes/recent.html"
},
{
"tags": [
"product"
],
"url": "https://pypi.org/project/django-allauth/"
},
{
"tags": [
"patch"
],
"url": "https://codeberg.org/allauth/django-allauth/commit/4379e7931fe7572aacc4f3b4b5f2298d5f3ecc96"
},
{
"tags": [
"patch"
],
"url": "https://codeberg.org/allauth/django-allauth/commit/4e252aa2be7cef5d72d78049d6fb07cb27a89c83"
},
{
"tags": [
"technical-description",
"related"
],
"url": "https://codeberg.org/allauth/django-allauth/commit/ae472772c8f93bcb972205c9d7159051cf6f413a"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Upgrade django-allauth to version 65.19.4 (latest). \u003cbr\u003e"
}
],
"value": "Upgrade django-allauth to version 65.19.4 (latest)."
}
],
"workarounds": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "The vulnerability is NOT exposed if any of the following settings is enabled.\u003cbr\u003e\u003cbr\u003e\u003cspan style=\"background-color: rgb(255, 255, 255)\"\u003e65.4 \u003c/span\u003e\u003cspan style=\"background-color: rgb(255, 255, 255)\"\u003eand later:\u003c/span\u003e\u003cbr\u003eACCOUNT_LOGIN_METHODS = {\"email\"}\u003cbr\u003e\u003cbr\u003e65.3 and earlier:\u003cbr\u003eACCOUNT_AUTHENTICATION_METHOD = \"email\"\u003cbr\u003e"
}
],
"value": "The vulnerability is NOT exposed if any of the following settings is enabled.\n\n65.4 and later:\nACCOUNT_LOGIN_METHODS = {\"email\"}\n\n65.3 and earlier:\nACCOUNT_AUTHENTICATION_METHOD = \"email\""
}
],
"x_generator": {
"engine": "CVE-Request-form 0.0.1"
}
}
},
"cveMetadata": {
"assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"assignerShortName": "mitre",
"cveId": "CVE-2026-97764",
"datePublished": "2026-09-25T04:25:57.932Z",
"dateReserved": "2026-09-25T04:25:57.123Z",
"dateUpdated": "2026-09-25T13:37:50.367Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-27982 (GCVE-0-2026-27982)
Vulnerability from nvd – Published: 2026-03-05 05:31 – Updated: 2026-03-06 18:19
VLAI
EPSS
VEX
Summary
An open redirect vulnerability exists in django-allauth versions prior to 65.14.1 when SAML IdP initiated SSO is enabled (it is disabled by default), which may allow an attacker to redirect users to an arbitrary external website via a crafted URL.
Severity
4.3 (Medium)
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-03-06 18:19 UTC
CWE
- CWE-601 - URL redirection to untrusted site ('Open Redirect')
Assigner
References
2 references
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| allauth | django-allauth |
Affected:
prior to 65.14.1
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-27982",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-03-06T18:19:44.307456Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-03-06T18:19:55.985Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "django-allauth",
"vendor": "allauth",
"versions": [
{
"status": "affected",
"version": "prior to 65.14.1"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An open redirect vulnerability exists in django-allauth versions prior to 65.14.1 when SAML IdP initiated SSO is enabled (it is disabled by default), which may allow an attacker to redirect users to an arbitrary external website via a crafted URL."
}
],
"metrics": [
{
"cvssV3_0": {
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N",
"version": "3.0"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en-US",
"value": "GENERAL"
}
]
},
{
"cvssV4_0": {
"baseScore": 5.1,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N",
"version": "4.0"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en-US",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-601",
"description": "URL redirection to untrusted site (\u0027Open Redirect\u0027)",
"lang": "en-US",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-03-05T05:31:25.711Z",
"orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"shortName": "jpcert"
},
"references": [
{
"url": "https://allauth.org/news/2026/02/django-allauth-65.14.1-released/"
},
{
"url": "https://jvn.jp/en/jp/JVN23669411/"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"assignerShortName": "jpcert",
"cveId": "CVE-2026-27982",
"datePublished": "2026-03-05T05:31:25.711Z",
"dateReserved": "2026-02-25T04:48:37.210Z",
"dateUpdated": "2026-03-06T18:19:55.985Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2025-65431 (GCVE-0-2025-65431)
Vulnerability from nvd – Published: 2025-12-15 00:00 – Updated: 2025-12-16 15:46
VLAI
EPSS
VEX
Summary
An issue was discovered in allauth-django before 65.13.0. Both Okta and NetIQ were using preferred_username as the identifier for third-party provider accounts. That value may be mutable and should therefore be avoided for authorization decisions. The providers are now using sub instead.
Severity
5.4 (Medium)
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2025-12-16 15:45 UTC
CWE
- n/a
- CWE-287 - Improper Authentication
Assigner
References
1 reference
{
"containers": {
"adp": [
{
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5.4,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
"version": "3.1"
}
},
{
"other": {
"content": {
"id": "CVE-2025-65431",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-12-16T15:45:27.702114Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-287",
"description": "CWE-287 Improper Authentication",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2025-12-16T15:46:43.345Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "n/a",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An issue was discovered in allauth-django before 65.13.0. Both Okta and NetIQ were using preferred_username as the identifier for third-party provider accounts. That value may be mutable and should therefore be avoided for authorization decisions. The providers are now using sub instead."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "n/a",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2025-12-15T14:12:05.967Z",
"orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"shortName": "mitre"
},
"references": [
{
"url": "https://allauth.org/news/2025/10/django-allauth-65.13.0-released/"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"assignerShortName": "mitre",
"cveId": "CVE-2025-65431",
"datePublished": "2025-12-15T00:00:00.000Z",
"dateReserved": "2025-11-18T00:00:00.000Z",
"dateUpdated": "2025-12-16T15:46:43.345Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2025-65430 (GCVE-0-2025-65430)
Vulnerability from nvd – Published: 2025-12-15 00:00 – Updated: 2025-12-15 15:40
VLAI
EPSS
VEX
Summary
An issue was discovered in allauth-django before 65.13.0. IdP: marking a user as is_active=False after having handed tokens for that user while the account was still active had no effect. Fixed the access/refresh tokens are now rejected.
Severity
5.4 (Medium)
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2025-12-15 15:40 UTC
CWE
- n/a
- CWE-613 - Insufficient Session Expiration
Assigner
References
1 reference
{
"containers": {
"adp": [
{
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5.4,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
"version": "3.1"
}
},
{
"other": {
"content": {
"id": "CVE-2025-65430",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-12-15T15:40:21.111048Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-613",
"description": "CWE-613 Insufficient Session Expiration",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2025-12-15T15:40:25.050Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "n/a",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An issue was discovered in allauth-django before 65.13.0. IdP: marking a user as is_active=False after having handed tokens for that user while the account was still active had no effect. Fixed the access/refresh tokens are now rejected."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "n/a",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2025-12-15T14:12:05.154Z",
"orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"shortName": "mitre"
},
"references": [
{
"url": "https://allauth.org/news/2025/10/django-allauth-65.13.0-released/"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"assignerShortName": "mitre",
"cveId": "CVE-2025-65430",
"datePublished": "2025-12-15T00:00:00.000Z",
"dateReserved": "2025-11-18T00:00:00.000Z",
"dateUpdated": "2025-12-15T15:40:25.050Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-97764 (GCVE-0-2026-97764)
Vulnerability from cvelistv5 – Published: 2026-09-25 04:25 – Updated: 2026-09-25 13:37
VLAI
EPSS
VEX
Summary
django-allauth before 65.19.4 does not have the expected limits on failed login attempts because, in some common configurations, an attacker can leverage the handling of diacritics (e.g., accents) for a higher effective limit.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-25 13:37 UTC
CWE
- CWE-180 - Incorrect Behavior Order: Validate Before Canonicalize
Assigner
References
5 references
| URL | Tags |
|---|---|
| https://docs.allauth.org/en/latest/release-notes/… | release-notes |
| https://pypi.org/project/django-allauth/ | product |
| https://codeberg.org/allauth/django-allauth/commi… | patch |
| https://codeberg.org/allauth/django-allauth/commi… | patch |
| https://codeberg.org/allauth/django-allauth/commi… | technical-descriptionrelated |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| allauth | django-allauth |
Affected:
0.25.0 , < 65.19.4
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-97764",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-25T13:37:23.042548Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-25T13:37:50.367Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"collectionURL": "https://pypi.org",
"defaultStatus": "unaffected",
"modules": [
"allauth.account.utils",
"allauth.account.adapter.DefaultAccountAdapter"
],
"packageName": "django-allauth",
"packageURL": "pkg:pypi/django-allauth",
"product": "django-allauth",
"programFiles": [
"allauth/account/utils.py",
"allauth/account/adapter.py"
],
"programRoutines": [
{
"name": "allauth.account.utils.filter_users_by_username()"
},
{
"name": "allauth.account.utils.filter_users_by_email()"
},
{
"name": "allauth.account.utils._unicode_ci_compare()"
},
{
"name": "allauth.account.adapter.DefaultAccountAdapter._get_login_attempts_cache_key()"
}
],
"repo": "https://codeberg.org/allauth/django-allauth",
"vendor": "allauth",
"versions": [
{
"lessThan": "65.19.4",
"status": "affected",
"version": "0.25.0",
"versionType": "custom"
}
]
}
],
"configurations": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "1. Any of the following settings is enabled in Django configuration.\u003cbr\u003e \u003cbr\u003e\u003cspan style=\"background-color: rgb(255, 255, 255)\"\u003e65.4\u0026nbsp;\u003c/span\u003e\u003cspan style=\"background-color: rgb(255, 255, 255)\"\u003eand later:\u003cbr\u003e\u003c/span\u003eACCOUNT_LOGIN_METHODS = {\"username\", \"email\"}\u003cbr\u003eACCOUNT_LOGIN_METHODS = {\"username\"}\u003cbr\u003e\u003cspan style=\"background-color: rgb(255, 255, 255)\"\u003e\u003cbr\u003e65.3 and earlier:\u003c/span\u003e\u003cbr\u003e\u003cspan style=\"background-color: rgb(255, 255, 255)\"\u003e\u003cspan style=\"background-color: rgb(255, 255, 255)\"\u003eACCOUNT_AUTHENTICATION_METHOD = \"username_email\"\u003c/span\u003e\u003cbr\u003eACCOUNT_AUTHENTICATION_METHOD = \"username\"\u003cbr\u003e\u003cbr\u003e\u003c/span\u003e2. The username column in the database uses a collation such as utf8mb4_general_ci or utf8mb4_unicode_ci.\u003cbr\u003e\u003cbr\u003e"
}
],
"value": "1. Any of the following settings is enabled in Django configuration.\n \n65.4\u00a0and later:\nACCOUNT_LOGIN_METHODS = {\"username\", \"email\"}\nACCOUNT_LOGIN_METHODS = {\"username\"}\n\n65.3 and earlier:\nACCOUNT_AUTHENTICATION_METHOD = \"username_email\"\nACCOUNT_AUTHENTICATION_METHOD = \"username\"\n\n2. The username column in the database uses a collation such as utf8mb4_general_ci or utf8mb4_unicode_ci."
}
],
"descriptions": [
{
"lang": "en",
"value": "django-allauth before 65.19.4 does not have the expected limits on failed login attempts because, in some common configurations, an attacker can leverage the handling of diacritics (e.g., accents) for a higher effective limit."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 3.7,
"baseSeverity": "LOW",
"confidentialityImpact": "NONE",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-180",
"description": "CWE-180 Incorrect Behavior Order: Validate Before Canonicalize",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-25T04:25:57.932Z",
"orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"shortName": "mitre"
},
"references": [
{
"tags": [
"release-notes"
],
"url": "https://docs.allauth.org/en/latest/release-notes/recent.html"
},
{
"tags": [
"product"
],
"url": "https://pypi.org/project/django-allauth/"
},
{
"tags": [
"patch"
],
"url": "https://codeberg.org/allauth/django-allauth/commit/4379e7931fe7572aacc4f3b4b5f2298d5f3ecc96"
},
{
"tags": [
"patch"
],
"url": "https://codeberg.org/allauth/django-allauth/commit/4e252aa2be7cef5d72d78049d6fb07cb27a89c83"
},
{
"tags": [
"technical-description",
"related"
],
"url": "https://codeberg.org/allauth/django-allauth/commit/ae472772c8f93bcb972205c9d7159051cf6f413a"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Upgrade django-allauth to version 65.19.4 (latest). \u003cbr\u003e"
}
],
"value": "Upgrade django-allauth to version 65.19.4 (latest)."
}
],
"workarounds": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "The vulnerability is NOT exposed if any of the following settings is enabled.\u003cbr\u003e\u003cbr\u003e\u003cspan style=\"background-color: rgb(255, 255, 255)\"\u003e65.4 \u003c/span\u003e\u003cspan style=\"background-color: rgb(255, 255, 255)\"\u003eand later:\u003c/span\u003e\u003cbr\u003eACCOUNT_LOGIN_METHODS = {\"email\"}\u003cbr\u003e\u003cbr\u003e65.3 and earlier:\u003cbr\u003eACCOUNT_AUTHENTICATION_METHOD = \"email\"\u003cbr\u003e"
}
],
"value": "The vulnerability is NOT exposed if any of the following settings is enabled.\n\n65.4 and later:\nACCOUNT_LOGIN_METHODS = {\"email\"}\n\n65.3 and earlier:\nACCOUNT_AUTHENTICATION_METHOD = \"email\""
}
],
"x_generator": {
"engine": "CVE-Request-form 0.0.1"
}
}
},
"cveMetadata": {
"assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"assignerShortName": "mitre",
"cveId": "CVE-2026-97764",
"datePublished": "2026-09-25T04:25:57.932Z",
"dateReserved": "2026-09-25T04:25:57.123Z",
"dateUpdated": "2026-09-25T13:37:50.367Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-27982 (GCVE-0-2026-27982)
Vulnerability from cvelistv5 – Published: 2026-03-05 05:31 – Updated: 2026-03-06 18:19
VLAI
EPSS
VEX
Summary
An open redirect vulnerability exists in django-allauth versions prior to 65.14.1 when SAML IdP initiated SSO is enabled (it is disabled by default), which may allow an attacker to redirect users to an arbitrary external website via a crafted URL.
Severity
4.3 (Medium)
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-03-06 18:19 UTC
CWE
- CWE-601 - URL redirection to untrusted site ('Open Redirect')
Assigner
References
2 references
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| allauth | django-allauth |
Affected:
prior to 65.14.1
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-27982",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-03-06T18:19:44.307456Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-03-06T18:19:55.985Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "django-allauth",
"vendor": "allauth",
"versions": [
{
"status": "affected",
"version": "prior to 65.14.1"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An open redirect vulnerability exists in django-allauth versions prior to 65.14.1 when SAML IdP initiated SSO is enabled (it is disabled by default), which may allow an attacker to redirect users to an arbitrary external website via a crafted URL."
}
],
"metrics": [
{
"cvssV3_0": {
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N",
"version": "3.0"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en-US",
"value": "GENERAL"
}
]
},
{
"cvssV4_0": {
"baseScore": 5.1,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N",
"version": "4.0"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en-US",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-601",
"description": "URL redirection to untrusted site (\u0027Open Redirect\u0027)",
"lang": "en-US",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-03-05T05:31:25.711Z",
"orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"shortName": "jpcert"
},
"references": [
{
"url": "https://allauth.org/news/2026/02/django-allauth-65.14.1-released/"
},
{
"url": "https://jvn.jp/en/jp/JVN23669411/"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"assignerShortName": "jpcert",
"cveId": "CVE-2026-27982",
"datePublished": "2026-03-05T05:31:25.711Z",
"dateReserved": "2026-02-25T04:48:37.210Z",
"dateUpdated": "2026-03-06T18:19:55.985Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2025-65430 (GCVE-0-2025-65430)
Vulnerability from cvelistv5 – Published: 2025-12-15 00:00 – Updated: 2025-12-15 15:40
VLAI
EPSS
VEX
Summary
An issue was discovered in allauth-django before 65.13.0. IdP: marking a user as is_active=False after having handed tokens for that user while the account was still active had no effect. Fixed the access/refresh tokens are now rejected.
Severity
5.4 (Medium)
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2025-12-15 15:40 UTC
CWE
- n/a
- CWE-613 - Insufficient Session Expiration
Assigner
References
1 reference
{
"containers": {
"adp": [
{
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5.4,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
"version": "3.1"
}
},
{
"other": {
"content": {
"id": "CVE-2025-65430",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-12-15T15:40:21.111048Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-613",
"description": "CWE-613 Insufficient Session Expiration",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2025-12-15T15:40:25.050Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "n/a",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An issue was discovered in allauth-django before 65.13.0. IdP: marking a user as is_active=False after having handed tokens for that user while the account was still active had no effect. Fixed the access/refresh tokens are now rejected."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "n/a",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2025-12-15T14:12:05.154Z",
"orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"shortName": "mitre"
},
"references": [
{
"url": "https://allauth.org/news/2025/10/django-allauth-65.13.0-released/"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"assignerShortName": "mitre",
"cveId": "CVE-2025-65430",
"datePublished": "2025-12-15T00:00:00.000Z",
"dateReserved": "2025-11-18T00:00:00.000Z",
"dateUpdated": "2025-12-15T15:40:25.050Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2025-65431 (GCVE-0-2025-65431)
Vulnerability from cvelistv5 – Published: 2025-12-15 00:00 – Updated: 2025-12-16 15:46
VLAI
EPSS
VEX
Summary
An issue was discovered in allauth-django before 65.13.0. Both Okta and NetIQ were using preferred_username as the identifier for third-party provider accounts. That value may be mutable and should therefore be avoided for authorization decisions. The providers are now using sub instead.
Severity
5.4 (Medium)
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2025-12-16 15:45 UTC
CWE
- n/a
- CWE-287 - Improper Authentication
Assigner
References
1 reference
{
"containers": {
"adp": [
{
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5.4,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
"version": "3.1"
}
},
{
"other": {
"content": {
"id": "CVE-2025-65431",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-12-16T15:45:27.702114Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-287",
"description": "CWE-287 Improper Authentication",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2025-12-16T15:46:43.345Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "n/a",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An issue was discovered in allauth-django before 65.13.0. Both Okta and NetIQ were using preferred_username as the identifier for third-party provider accounts. That value may be mutable and should therefore be avoided for authorization decisions. The providers are now using sub instead."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "n/a",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2025-12-15T14:12:05.967Z",
"orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"shortName": "mitre"
},
"references": [
{
"url": "https://allauth.org/news/2025/10/django-allauth-65.13.0-released/"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"assignerShortName": "mitre",
"cveId": "CVE-2025-65431",
"datePublished": "2025-12-15T00:00:00.000Z",
"dateReserved": "2025-11-18T00:00:00.000Z",
"dateUpdated": "2025-12-16T15:46:43.345Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
JVNDB-2026-000034
Vulnerability from jvndb - Published: 2026-03-05 03:36 - Updated:2026-03-05 03:36
Severity
Summary
django-allauth vulnerable to open redirect
Details
django-allauth is a package for implementing user authentication in Django applications. django-allauth contains the following vulnerability.
- Open redirect (CWE-601) - CVE-2026-27982
References
| Type | URL | |
|---|---|---|
Impacted products
| Vendor | Product | |
|---|---|---|
{
"@rdf:about": "https://jvndb.jvn.jp/en/contents/2026/JVNDB-2026-000034.html",
"dc:date": "2026-03-05T12:36+09:00",
"dcterms:issued": "2026-03-05T12:36+09:00",
"dcterms:modified": "2026-03-05T12:36+09:00",
"description": "django-allauth is a package for implementing user authentication in Django applications. django-allauth contains the following vulnerability.\u003ca href=\u0027https://cwe.mitre.org/data/definitions/601.html\u0027 target=\u0027_blank\u0027\u003e\u003c/a\u003e\u003cul\u003e\u003cli\u003eOpen redirect (CWE-601) - CVE-2026-27982\u003c/li\u003e\u003c/ul\u003eAyato Shitomi of Fore-Z co.ltd and Funabiki Keisuke of GMO Cybersecurity by Ierae, Inc. reported this vulnerability to the developer and coordinated. After the coordination was completed, Ayato Shitomi and Funabiki Keisuke reported the case to JPCERT/CC to notify users of the solution through JVN.",
"link": "https://jvndb.jvn.jp/en/contents/2026/JVNDB-2026-000034.html",
"sec:cpe": {
"#text": "cpe:/a:allauth:django-allauth",
"@product": "django-allauth",
"@vendor": "allauth",
"@version": "2.2"
},
"sec:cvss": {
"@score": "4.3",
"@severity": "Medium",
"@type": "Base",
"@vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N",
"@version": "3.0"
},
"sec:identifier": "JVNDB-2026-000034",
"sec:references": [
{
"#text": "https://jvn.jp/en/jp/JVN23669411/index.html",
"@id": "JVN#23669411",
"@source": "JVN"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2026-27982",
"@id": "CVE-2026-27982",
"@source": "CVE"
},
{
"#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
"@id": "CWE-Other",
"@title": "No Mapping(CWE-Other)"
}
],
"title": "django-allauth vulnerable to open redirect"
}