django-allauth before 65.19.4 does not have the expected limits on failed login attempts because, in some common configurations, an attacker can leverage the handling of diacritics (e.g., accents) for a higher effective limit.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
Upgrade django-allauth to version 65.19.4 (latest).
Workaround
The vulnerability is NOT exposed if any of the following settings is enabled. 65.4 and later: ACCOUNT_LOGIN_METHODS = {"email"} 65.3 and earlier: ACCOUNT_AUTHENTICATION_METHOD = "email"
References
History
Fri, 25 Sep 2026 04:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | django-allauth before 65.19.4 does not have the expected limits on failed login attempts because, in some common configurations, an attacker can leverage the handling of diacritics (e.g., accents) for a higher effective limit. | |
| Weaknesses | CWE-180 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-09-25T04:25:57.932Z
Reserved: 2026-09-25T04:25:57.123Z
Link: CVE-2026-97764
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses