VulnSea

python-social-auth has 5 CVEs on record. 5 were published in the last 90 days. The busiest recent month was September 2026 with 5. The median CVSS is 6.4 (medium). None have a confirmed exploitation report.

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.4
Publish → KEV
—
Last 90 days
5 prev 0

Products

  • social-core 5
5
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

python-social-auth vulnerabilities

CVEs affecting python-social-auth, newest first. Open any entry for full detail, references, and exploit status.

5 CVEsRSS

CVE-2026-57175Medium· 6.4
today

Python Social Auth is a social authentication/registration mechanism

Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the SAML backend accepted SAML responses on the Assertion Consumer Service endpoint without verifying that they matched a previously issued `Au…

▾ Sunlitpython-social-auth · social-corevia NVD
CVE-2026-57178High· 7.4
today

Python Social Auth is a social authentication/registration mechanism

Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the `vk-app` backend accepted VK application callback data without verifying the callback signature when the `auth_key` parameter was omitted. …

▾ Twilightpython-social-auth · social-corevia NVD
CVE-2026-57176Medium· 6.8
today

Python Social Auth is a social authentication/registration mechanism

Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the Vend OAuth2 backend used only the numeric Vend user_id as the social-auth UID. When multiple Vend shops authenticate through the same appli…

▾ Sunlitpython-social-auth · social-corevia NVD
CVE-2026-57177Medium· 4.3
today

Python Social Auth is a social authentication/registration mechanism

Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the LoginRadius backend did not validate OAuth state during the authentication flow. Applications using this backend were vulnerable to login C…

▾ Sunlitpython-social-auth · social-corevia NVD
CVE-2026-57179Medium· 4.2
today

Python Social Auth is a social authentication/registration mechanism

Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the partial-pipeline resume mechanism accepted `partial_token` as a bearer credential without binding it to the browser session that created it…

▾ Sunlitpython-social-auth · social-corevia NVD
python-social-auth vulnerabilities (CVEs) · VulnSea