social-auth-core
PyPI5 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting social-auth-corepage 1 of 1
- CVE-2026-57175MEDIUMCVSS 6.4EG 6.4✓ Fixed in 5.0.02026-09-24
vulnerable: 0.0.1 ... 4.9.1 (50 versions)
Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the SAML backend accepted SAML responses on the Assertion Consumer Service endpoint without verifying that they matched a previously issued `Auth…
- CVE-2026-57176MEDIUMCVSS 6.8EG 6.8✓ Fixed in 5.0.02026-09-24
vulnerable: 0.0.1 ... 4.9.1 (50 versions)
Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the Vend OAuth2 backend used only the numeric Vend user_id as the social-auth UID. When multiple Vend shops authenticate through the same applica…
- CVE-2026-57177MEDIUMCVSS 4.3EG 4.3✓ Fixed in 5.0.02026-09-24
vulnerable: 0.0.1 ... 4.9.1 (50 versions)
Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the LoginRadius backend did not validate OAuth state during the authentication flow. Applications using this backend were vulnerable to login CSR…
- CVE-2026-57178HIGHCVSS 7.4EG 7.4✓ Fixed in 5.0.02026-09-24
vulnerable: 0.0.1 ... 4.9.1 (50 versions)
Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the `vk-app` backend accepted VK application callback data without verifying the callback signature when the `auth_key` parameter was omitted. Ap…
- CVE-2026-57179MEDIUMCVSS 4.2EG 4.2✓ Fixed in 5.0.02026-09-24
vulnerable: 0.0.1 ... 4.9.1 (50 versions)
Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the partial-pipeline resume mechanism accepted `partial_token` as a bearer credential without binding it to the browser session that created it. …
Check whether social-auth-core is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for social-auth-core CVEs against the assets you own.
Book a Demo →