Login Attempt Limitation Flaw in Django-Allauth by Vinay S.
CVE-2026-97764
3.7LOW
What is CVE-2026-97764?
The Django-Allauth library, prior to version 65.19.4, exhibits a vulnerability where it lacks appropriate restrictions on failed login attempts. This loophole can be exploited, particularly in scenarios involving standardized configurations, allowing attackers to manipulate the handling of diacritics such as accents. This can effectively result in an elevated limit on the number of login attempts, thereby increasing the risk of successful brute-force attacks.
Affected Version(s)
django-allauth 0.25.0 < 65.19.4
