Update dependency django-allauth to v65 [SECURITY] - #2711
Open
renovate[bot] wants to merge 1 commit into
Open
Conversation
renovate
Bot
force-pushed
the
renovate/pypi-django-allauth-vulnerability
branch
from
March 6, 2026 02:05
249e359 to
64ad70e
Compare
renovate
Bot
force-pushed
the
renovate/pypi-django-allauth-vulnerability
branch
2 times, most recently
from
March 30, 2026 22:13
64ad70e to
bfbf518
Compare
renovate
Bot
force-pushed
the
renovate/pypi-django-allauth-vulnerability
branch
2 times, most recently
from
April 27, 2026 22:34
bfbf518 to
46c7c76
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
==0.55.0→==65.14.1django-allauth does not reject access tokens for inactive users
CVE-2025-65430 / GHSA-qhmc-3mvr-f2j4
More information
Details
An issue was discovered in allauth-django before 65.13.0. IdP: marking a user as is_active=False after having handed tokens for that user while the account was still active had no effect. Fixed the access/refresh tokens are now rejected.
Severity
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
django-allauth's Okta and NetIQ implementations used a mutable identifier for authorization decisions
CVE-2025-65431 / GHSA-8m3c-c723-h4p4
More information
Details
An issue was discovered in allauth-django before 65.13.0. Both Okta and NetIQ were using preferred_username as the identifier for third-party provider accounts. That value may be mutable and should therefore be avoided for authorization decisions. The providers are now using sub instead.
Severity
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
django-allauth has an open redirect vulnerability
CVE-2026-27982 / GHSA-2jpr-83rg-v67j
More information
Details
An open redirect vulnerability exists in django-allauth versions prior to 65.14.1 when SAML IdP initiated SSO is enabled (it is disabled by default), which may allow an attacker to redirect users to an arbitrary external website via a crafted URL.
Severity
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
allauth/django-allauth (django-allauth)
v65.14.1Compare Source
v65.14.0Compare Source
v65.13.1Compare Source
v65.13.0Compare Source
v65.12.1Compare Source
v65.12.0Compare Source
v65.11.2Compare Source
v65.11.1Compare Source
v65.11.0Compare Source
v65.10.0Compare Source
v65.9.0Compare Source
v65.8.1Compare Source
v65.8.0Compare Source
v65.7.0Compare Source
v65.6.0Compare Source
v65.5.0Compare Source
v65.4.1Compare Source
v65.4.0Compare Source
v65.3.1Compare Source
v65.3.0Compare Source
v65.2.0Compare Source
v65.1.0Compare Source
v65.0.2Compare Source
v65.0.1Compare Source
v65.0.0Compare Source
v64.2.1Compare Source
v64.2.0Compare Source
v64.1.0Compare Source
v64.0.0Compare Source
v0.63.6Compare Source
v0.63.5Compare Source
v0.63.4Compare Source
v0.63.3Compare Source
v0.63.2Compare Source
v0.63.1Compare Source
v0.63.0Compare Source
v0.62.1Compare Source
v0.62.0Compare Source
v0.61.1Compare Source
v0.61.0Compare Source
v0.60.1Compare Source
v0.60.0Compare Source
v0.59.0Compare Source
v0.58.2Compare Source
v0.58.1Compare Source
v0.58.0Compare Source
v0.57.2Compare Source
v0.57.1Compare Source
v0.57.0Compare Source
v0.56.1Compare Source
v0.56.0Compare Source
v0.55.2Compare Source
v0.55.1Compare Source
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.