Open Redirect Vulnerability in Django-Allauth by Django
CVE-2026-27982

5.1MEDIUM

Key Information:

Vendor

Allauth

Vendor
CVE Published:
5 March 2026

What is CVE-2026-27982?

An open redirect vulnerability exists in certain versions of Django-Allauth when SAML IdP initiated Single Sign-On (SSO) is enabled. This flaw allows attackers to craft malicious URLs that may redirect users to arbitrary external websites, potentially leading to phishing attacks or other security risks. The vulnerability affects all versions of django-allauth prior to 65.14.1 when the SSO feature is active, highlighting the importance of keeping software updated to mitigate risks.

Affected Version(s)

django-allauth prior to 65.14.1

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

CVSS V3.0

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.