CVE-2026-27982

EUVD-2026-9652
An open redirect vulnerability exists in django-allauth versions prior to 65.14.1 when SAML IdP initiated SSO is enabled (it is disabled by default), which may allow an attacker to redirect users to an arbitrary external website via a crafted URL.
Open Redirect
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.1 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
allauthallauth
𝑥
< 65.14.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
django-allauth
bookworm
no-dsa
bullseye
postponed
forky
65.15.0-1
fixed
sid
65.15.0-1
fixed
trixie
no-dsa