CVE-2025-65431: Medium severity pypi/allauth-django vulnerability
An issue was discovered in allauth-django before 65.13.0. Both Okta and NetIQ were using preferredusername as the identifier for third-party provider accounts. That value may be mutable and should therefore be avoided for authorization decisions. The providers are now using sub instead.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-65431?
CVE-2025-65431 is classified as a moderate severity vulnerability due to the potential for unauthorized access based on mutable identifiers.
How do I fix CVE-2025-65431?
To mitigate CVE-2025-65431, you should upgrade allauth-django to version 65.13.0 or later, where the issue has been addressed.
What are the risks associated with CVE-2025-65431?
The risk associated with CVE-2025-65431 involves potential unauthorized access and identity manipulation in systems using mutable identifiers for authorization.
What systems are affected by CVE-2025-65431?
CVE-2025-65431 affects allauth-django versions prior to 65.13.0, specifically in implementations using Okta and NetIQ.
When was CVE-2025-65431 disclosed?
CVE-2025-65431 was disclosed alongside the release of version 65.13.0 of allauth-django in October 2025.