social-core vulnerabilities
CVEs whose affected-version data names the social-core package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
5 CVEsRSS
CVE-2026-57175Medium· 6.4Python Social Auth is a social authentication/registration mechanism
Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the SAML backend accepted SAML responses on the Assertion Consumer Service endpoint without verifying that they matched a previously issued `Au…
CVE-2026-57178High· 7.4Python Social Auth is a social authentication/registration mechanism
Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the `vk-app` backend accepted VK application callback data without verifying the callback signature when the `auth_key` parameter was omitted. …
CVE-2026-57176Medium· 6.8Python Social Auth is a social authentication/registration mechanism
Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the Vend OAuth2 backend used only the numeric Vend user_id as the social-auth UID. When multiple Vend shops authenticate through the same appli…
CVE-2026-57177Medium· 4.3Python Social Auth is a social authentication/registration mechanism
Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the LoginRadius backend did not validate OAuth state during the authentication flow. Applications using this backend were vulnerable to login C…
CVE-2026-57179Medium· 4.2Python Social Auth is a social authentication/registration mechanism
Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the partial-pipeline resume mechanism accepted `partial_token` as a bearer credential without binding it to the browser session that created it…