Login Attempt Limitation Flaw in Django-Allauth by Vinay S.
CVE-2026-97764

3.7LOW

Key Information:

Vendor

Allauth

Vendor
CVE Published:
25 September 2026

What is CVE-2026-97764?

The Django-Allauth library, prior to version 65.19.4, exhibits a vulnerability where it lacks appropriate restrictions on failed login attempts. This loophole can be exploited, particularly in scenarios involving standardized configurations, allowing attackers to manipulate the handling of diacritics such as accents. This can effectively result in an elevated limit on the number of login attempts, thereby increasing the risk of successful brute-force attacks.

Affected Version(s)

django-allauth 0.25.0 < 65.19.4

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.