CVE-2025-65430: Medium severity pypi/allauth-django vulnerability
Published Dec 15, 2025
·Updated
An issue was discovered in allauth-django before 65.13.0. IdP: marking a user as isactive=False after having handed tokens for that user while the account was still active had no effect. Fixed the access/refresh tokens are now rejected.
Affected Software
3 affected componentsFixes available
pypi/allauth-django<65.13.0
pip/django-allauth<65.13.0
65.13.0
allauth Allauth Django<65.13.0
Event History
Dec 15, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
Affected Software
Advisory Published
via GitHub·03:30 PM
Data Sourced
via GitHub·03:30 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-65430?
CVE-2025-65430 is classified as a medium severity vulnerability.
2
How do I fix CVE-2025-65430?
To fix CVE-2025-65430, upgrade allauth-django to version 65.13.0 or later.
3
What does CVE-2025-65430 affect?
CVE-2025-65430 affects all versions of allauth-django prior to 65.13.0.
4
What is the impact of CVE-2025-65430 on user accounts?
CVE-2025-65430 can allow users marked as inactive to still be able to use their tokens, leading to unauthorized access until the issue is resolved.
5
How was CVE-2025-65430 mitigated?
CVE-2025-65430 was mitigated by implementing a fix that rejects access and refresh tokens for users marked as inactive.