vulnti.work

django-allauth before 65.19.4 does not have the expected limits on failed login attempts because, in some common configurations, an attacker can leverage the handling of diacritics (e.g., accents) fo…

Low CVSS 3.7
CVECVE-2026-97764
First seen2026-09-25 07:16 UTC
Disclosed2026-09-25 05:17 UTC
Last updated2026-09-25 07:16 UTC
Channel statusauto

Summary

django-allauth before 65.19.4 does not have the expected limits on failed login attempts because, in some common configurations, an attacker can leverage the handling of diacritics (e.g., accents) for a higher effective limit.

In-depth triage

No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).

Sources

  • NVD DATABASE

Original Links

Timeline

  1. nvd_ingest NVD