CVE-2026-27982
MEDIUMdjango-allauth <65.14.1 - Open Redirect
Title source: llmDescription
An open redirect vulnerability exists in django-allauth versions prior to 65.14.1 when SAML IdP initiated SSO is enabled (it is disabled by default), which may allow an attacker to redirect users to an arbitrary external website via a crafted URL.
Scores
CVSS v3
6.1
EPSS
0.0003
EPSS Percentile
8.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Classification
CWE
CWE-601
Status
published
Affected Products (2)
pypi/django-allauth
< 65.14.1PyPI
allauth/allauth
< 65.14.1
Timeline
Published
Mar 05, 2026
Tracked Since
Mar 05, 2026