CVE-2026-97764: Allauth Django-Allauth

Low severity, CVSS 3.7. EPSS: 0.2% chance of exploitation in the next 30 days.

django-allauth before 65.19.4 does not have the expected limits on failed login attempts because, in some common configurations, an attacker can leverage the handling of diacritics (e.g., accents) for a higher effective limit.

Affected products

  • Allauth Django-Allauth: from 0.25.0, before 65.19.4 (fixed in 65.19.4)

Published 2026-09-25. Last modified 2026-09-30.