CVE-2025-65431
15.12.2025, 14:15
An issue was discovered in allauth-django before 65.13.0. Both Okta and NetIQ were using preferred_username as the identifier for third-party provider accounts. That value may be mutable and should therefore be avoided for authorization decisions. The providers are now using sub instead.Enginsight
| Vendor | Product | Version |
|---|---|---|
| allauth | allauth | 𝑥 < 65.13.0 |
𝑥
= Vulnerable software versions
Debian Releases
Common Weakness Enumeration