PT-2026-98353 · Pypi · Allauth-Django
CVE-2026-97764
·
Published
2026-09-25
·
Updated
2026-09-28
CVSS v3.1
3.7
Low
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
django-allauth versions prior to 65.19.4
Description
In certain common configurations, the software fails to enforce expected limits on failed login attempts. An attacker can bypass these restrictions by leveraging the handling of diacritics, such as accents, to increase the effective number of allowed login attempts.
Recommendations
Update to version 65.19.4 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Allauth-Django