CVE-2026-97764EPSS p12.2%
CVE-2026-97764CVE-2026-97764
Description
django-allauth before 65.19.4 does not have the expected limits on failed login attempts because, in some common configurations, an attacker can leverage the handling of diacritics (e.g., accents) for a higher effective limit.
Scoring
| CVSS | 3.7 () |
| Vector | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N |
| EPSS | 0.23% probability of exploitation · percentile 12.2% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-30 |