CVE-2025-65431: Medium severity pypi/allauth-django vulnerability

Published Dec 15, 2025
·
Updated

An issue was discovered in allauth-django before 65.13.0. Both Okta and NetIQ were using preferredusername as the identifier for third-party provider accounts. That value may be mutable and should therefore be avoided for authorization decisions. The providers are now using sub instead.

Affected Software

3 affected componentsFixes available
pypi/allauth-django<65.13.0
pip/django-allauth<65.13.0
65.13.0
allauth Allauth Django<65.13.0

Event History

Dec 15, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·03:30 PM
Data Sourced
via GitHub·03:30 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2025-65431?

CVE-2025-65431 is classified as a moderate severity vulnerability due to the potential for unauthorized access based on mutable identifiers.

2

How do I fix CVE-2025-65431?

To mitigate CVE-2025-65431, you should upgrade allauth-django to version 65.13.0 or later, where the issue has been addressed.

3

What are the risks associated with CVE-2025-65431?

The risk associated with CVE-2025-65431 involves potential unauthorized access and identity manipulation in systems using mutable identifiers for authorization.

4

What systems are affected by CVE-2025-65431?

CVE-2025-65431 affects allauth-django versions prior to 65.13.0, specifically in implementations using Okta and NetIQ.

5

When was CVE-2025-65431 disclosed?

CVE-2025-65431 was disclosed alongside the release of version 65.13.0 of allauth-django in October 2025.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203