VulnSea

social-core vulnerabilities

CVEs whose affected-version data names the social-core package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

5 CVEsRSS

CVE-2026-57175Medium· 6.4
yesterday

Python Social Auth is a social authentication/registration mechanism

Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the SAML backend accepted SAML responses on the Assertion Consumer Service endpoint without verifying that they matched a previously issued `Au…

▾ Sunlitpython-social-auth · social-corevia NVD
CVE-2026-57178High· 7.4
yesterday

Python Social Auth is a social authentication/registration mechanism

Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the `vk-app` backend accepted VK application callback data without verifying the callback signature when the `auth_key` parameter was omitted. …

▾ Twilightpython-social-auth · social-corevia NVD
CVE-2026-57176Medium· 6.8
yesterday

Python Social Auth is a social authentication/registration mechanism

Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the Vend OAuth2 backend used only the numeric Vend user_id as the social-auth UID. When multiple Vend shops authenticate through the same appli…

▾ Sunlitpython-social-auth · social-corevia NVD
CVE-2026-57177Medium· 4.3
yesterday

Python Social Auth is a social authentication/registration mechanism

Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the LoginRadius backend did not validate OAuth state during the authentication flow. Applications using this backend were vulnerable to login C…

▾ Sunlitpython-social-auth · social-corevia NVD
CVE-2026-57179Medium· 4.2
yesterday

Python Social Auth is a social authentication/registration mechanism

Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the partial-pipeline resume mechanism accepted `partial_token` as a bearer credential without binding it to the browser session that created it…

▾ Sunlitpython-social-auth · social-corevia NVD
social-core vulnerabilities (CVEs) · VulnSea