An open redirect vulnerability exists in django-allauth versions prior to 65.14.1 when SAML IdP initiated SSO is enabled (it is disabled by default), which may allow an attacker to redirect users to an arbitrary external website via a crafted URL.
References
| Link | Resource |
|---|---|
| https://allauth.org/news/2026/02/django-allauth-65.14.1-released/ | Release Notes |
| https://jvn.jp/en/jp/JVN23669411/ | Third Party Advisory |
Configurations
History
09 Mar 2026, 18:41
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Allauth
Allauth allauth |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.1 |
| CPE | cpe:2.3:a:allauth:allauth:*:*:*:*:*:django:*:* | |
| References | () https://allauth.org/news/2026/02/django-allauth-65.14.1-released/ - Release Notes | |
| References | () https://jvn.jp/en/jp/JVN23669411/ - Third Party Advisory |
05 Mar 2026, 06:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-05 06:16
Updated : 2026-03-09 18:41
NVD link : CVE-2026-27982
Mitre link : CVE-2026-27982
CVE.ORG link : CVE-2026-27982
JSON object : View
Products Affected
allauth
- allauth
CWE
CWE-601
URL Redirection to Untrusted Site ('Open Redirect')
