We found results for “”
CVE-2025-65431
Good to know:
Date: December 15, 2025
An issue was discovered in allauth-django before 65.13.0. Both Okta and NetIQ were using preferred_username as the identifier for third-party provider accounts. That value may be mutable and should therefore be avoided for authorization decisions. The providers are now using sub instead.
Severity Score
Related Resources (6)
Severity Score
Weakness Type (CWE)
Improper Authentication
CWE-287Top Fix
Upgrade Version
Upgrade to version django-allauth - 65.13.0;django-allauth - 65.13.0;django-allauth - 65.13.0;https://github.com/pennersr/django-allauth.git - 65.13.0
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | NONE |
| User Interaction (UI): | NONE |
| Scope (S): | UNCHANGED |
| Confidentiality (C): | HIGH |
| Integrity (I): | NONE |
| Availability (A): | NONE |
Vulnerabilities
Projects
Contact Us


