Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade django-allauth to version 65.19.4 (latest).
Vendor Workaround
The vulnerability is NOT exposed if any of the following settings is enabled. 65.4 and later: ACCOUNT_LOGIN_METHODS = {"email"} 65.3 and earlier: ACCOUNT_AUTHENTICATION_METHOD = "email"
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 25 Sep 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Allauth
Allauth django-allauth |
|
| Vendors & Products |
Allauth
Allauth django-allauth |
Fri, 25 Sep 2026 04:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | django-allauth before 65.19.4 does not have the expected limits on failed login attempts because, in some common configurations, an attacker can leverage the handling of diacritics (e.g., accents) for a higher effective limit. | |
| Weaknesses | CWE-180 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-09-25T04:25:57.932Z
Reserved: 2026-09-25T04:25:57.123Z
Link: CVE-2026-97764
No data.
Status : Received
Published: 2026-09-25T05:17:07.953
Modified: 2026-09-25T05:17:07.953
Link: CVE-2026-97764
No data.
OpenCVE Enrichment
Updated: 2026-09-25T06:00:12Z