[Git][security-tracker-team/security-tracker][master] Add CVE-2026-97764/django-allauth
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Fri Sep 25 20:58:49 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
7979fd01 by Salvatore Bonaccorso at 2026-09-25T21:57:48+02:00
Add CVE-2026-97764/django-allauth
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -43,7 +43,9 @@ CVE-2026-97846 (Keycloak provides a feature called mTLS holder-of-key binding wh
CVE-2026-97818 (phpIPAM through 1.8.3 has incorrect authorization for id=="admins" and ...)
- phpipam <itp> (bug #731713)
CVE-2026-97764 (django-allauth before 65.19.4 does not have the expected limits on fai ...)
- TODO: check
+ - django-allauth <unfixed>
+ NOTE: Fixed by: https://codeberg.org/allauth/django-allauth/commit/4379e7931fe7572aacc4f3b4b5f2298d5f3ecc96 (65.19.4)
+ NOTE: Fixed by: https://codeberg.org/allauth/django-allauth/commit/4e252aa2be7cef5d72d78049d6fb07cb27a89c83 (65.19.4)
CVE-2026-97737 (In Wakapi before 2.17.6, the user caching service allows a lookup to b ...)
TODO: check
CVE-2026-97736 (tinyauth before 5.1.3 allows rule bypass by appending an allowed route ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7979fd01a7d96563a95eccb24d16218a4cb33e23
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7979fd01a7d96563a95eccb24d16218a4cb33e23
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260925/272418a5/attachment.htm>
More information about the debian-security-tracker-commits
mailing list