CVE-2026-27982

MEDIUM

django-allauth <65.14.1 - Open Redirect

Title source: llm

Description

An open redirect vulnerability exists in django-allauth versions prior to 65.14.1 when SAML IdP initiated SSO is enabled (it is disabled by default), which may allow an attacker to redirect users to an arbitrary external website via a crafted URL.

Scores

CVSS v3 6.1
EPSS 0.0003
EPSS Percentile 8.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Classification

CWE
CWE-601
Status published

Affected Products (2)

pypi/django-allauth < 65.14.1PyPI
allauth/allauth < 65.14.1

Timeline

Published Mar 05, 2026
Tracked Since Mar 05, 2026