Vulnerabilities
Vulnerable Software
Allauth:  >> Allauth  Security Vulnerabilities
An issue was discovered in allauth-django before 65.13.0. IdP: marking a user as is_active=False after having handed tokens for that user while the account was still active had no effect. Fixed the access/refresh tokens are now rejected.
CVSS Score
5.4
EPSS Score
0.0
Published
2025-12-15
An issue was discovered in allauth-django before 65.13.0. Both Okta and NetIQ were using preferred_username as the identifier for third-party provider accounts. That value may be mutable and should therefore be avoided for authorization decisions. The providers are now using sub instead.
CVSS Score
5.4
EPSS Score
0.0
Published
2025-12-15


Contact Us

Shodan ® - All rights reserved