CVE-2026-27982: Medium severity pypi/django-allauth vulnerability
An open redirect vulnerability exists in django-allauth versions prior to 65.14.1 when SAML IdP initiated SSO is enabled (it is disabled by default), which may allow an attacker to redirect users to an arbitrary external website via a crafted URL.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27982?
CVE-2026-27982 is categorized as a high severity vulnerability due to its potential for exploitation via open redirects.
How do I fix CVE-2026-27982?
To fix CVE-2026-27982, upgrade django-allauth to version 65.14.1 or later.
What causes CVE-2026-27982?
CVE-2026-27982 is caused by an open redirect vulnerability present in versions of django-allauth prior to 65.14.1 when SAML IdP initiated SSO is enabled.
Who is affected by CVE-2026-27982?
Any user or organization using django-allauth versions prior to 65.14.1 with SAML IdP initiated SSO enabled may be affected by CVE-2026-27982.
What is an open redirect vulnerability in CVE-2026-27982?
An open redirect vulnerability, as noted in CVE-2026-27982, allows attackers to redirect users to arbitrary external sites, potentially leading to phishing or malware.