CVE-2026-27982

MEDIUM WAF: Medium
CVSS 6.1 Published: 2026-03-05
CWE-601

An open redirect vulnerability exists in django-allauth versions prior to 65.14.1 when SAML IdP initiated SSO is enabled (it is disabled by default), which may allow an attacker to redirect users to an arbitrary external website via a crafted URL.

WAF Coverage Analysis

Open Redirect Medium WAF Coverage

OWASP: A01:2021 Broken Access Control

941xxx - XSS / XXE

Affected Software

VendorProductVersion
allauthallauthup to 65.14.1

References

Back to CVE Database