PatchSiren

allauth CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW allauth CVE published 2026-09-25

CVE-2026-97764

CVE-2026-97764 debrief: The django-allauth package before version 65.19.4 does not properly limit failed login attempts in certain configurations due to its handling of diacritics. This could potentially allow attackers to perform brute-force attacks on user accounts. Defenders responsible for authentication systems, especially those using django-allauth, should assess exposure and verify configurations. [truncated]