Brute Force Affecting django-allauth package, versions [0.25.0,65.19.4)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.23% (12th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Brute Force vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PYTHON-DJANGOALLAUTH-20158377
  • published27 Sept 2026
  • disclosed25 Sept 2026
  • creditUnknown

Introduced: 25 Sep 2026

NewCVE-2026-97764  (opens in a new tab)
CWE-307  (opens in a new tab)

How to fix?

Upgrade django-allauth to version 65.19.4 or higher.

Overview

django-allauth is an integrated set of Django applications addressing authentication, registration, account management as well as 3rd party (social) account authentication.

Affected versions of this package are vulnerable to Brute Force in the failed login attempt rate-limiting logic, an attacker can bypass the expected brute-force protection by submitting login attempts that include diacritics (e.g., accented characters). Because diacritic variants of a username or password are handled as distinct inputs in some common configurations, each variant consumes a separate slot in the failed attempt counter, effectively multiplying the number of attempts an attacker can make before being locked out.

CVSS Base Scores

version 4.0
version 3.1