CVE-2026-27982

MEDIUM

django-allauth <65.14.1 - Open Redirect

Title source: llm
STIX 2.1

Description

An open redirect vulnerability exists in django-allauth versions prior to 65.14.1 when SAML IdP initiated SSO is enabled (it is disabled by default), which may allow an attacker to redirect users to an arbitrary external website via a crafted URL.

Scores

CVSS v3 6.1
EPSS 0.0003
EPSS Percentile 9.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-601
Status published
Products (2)
allauth/allauth < 65.14.1
pypi/django-allauth 0 - 65.14.1PyPI
Published Mar 05, 2026
Tracked Since Mar 05, 2026