{"id":"CVE-2026-97764","title":"django-allauth before 65.19.4 does not have the expected limits on failed login attempts because, in some common configurations, an attacker can leverage the handling of diacritics (e.g., accents) for a higher effective limit.","summary":"django-allauth before 65.19.4 does not have the expected limits on failed login attempts because, in some common configurations, an attacker can leverage the handling of diacritics (e.g., accents) for a higher effective limit.","severity":"low","cvss":3.7,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","cwe":["CWE-180"],"vendor":"allauth","product":"django-allauth","affected":["django-allauth >= 0.25.0 < 65.19.4"],"published":"2026-09-25","updated":"2026-09-25","sourceUpdated":"2026-09-25T05:17:07.953","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-97764","references":[{"url":"https://codeberg.org/allauth/django-allauth/commit/4379e7931fe7572aacc4f3b4b5f2298d5f3ecc96","label":"cve@mitre.org"},{"url":"https://codeberg.org/allauth/django-allauth/commit/4e252aa2be7cef5d72d78049d6fb07cb27a89c83","label":"cve@mitre.org"},{"url":"https://codeberg.org/allauth/django-allauth/commit/ae472772c8f93bcb972205c9d7159051cf6f413a","label":"cve@mitre.org"},{"url":"https://docs.allauth.org/en/latest/release-notes/recent.html","label":"cve@mitre.org"},{"url":"https://pypi.org/project/django-allauth/","label":"cve@mitre.org"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-25T04:59:31.584Z","slug":"CVE-2026-97764","body":"## Overview\n\ndjango-allauth before 65.19.4 does not have the expected limits on failed login attempts because, in some common configurations, an attacker can leverage the handling of diacritics (e.g., accents) for a higher effective limit.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":20,"depthScoreParts":{"impact":20.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}