django-allauth
PyPI2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting django-allauthpage 1 of 1
- CVE-2025-65430MEDIUMCVSS 5.4EG 5.4✓ Fixed in 65.13.02025-12-15
vulnerable: 0.1.0 ... 65.9.0 (120 versions)
An issue was discovered in allauth-django before 65.13.0. IdP: marking a user as is_active=False after having handed tokens for that user while the account was still active had no effect. Fixed the access/refresh tokens are now rejected.
- CVE-2025-65431MEDIUMCVSS 5.4EG 5.4✓ Fixed in 65.13.02025-12-15
vulnerable: 0.1.0 ... 65.9.0 (120 versions)
An issue was discovered in allauth-django before 65.13.0. Both Okta and NetIQ were using preferred_username as the identifier for third-party provider accounts. That value may be mutable and should therefore be avoided for authorization de…
Check whether django-allauth is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for django-allauth CVEs against the assets you own.
Start Free Scan →