Skip to content
Info Published: Dec 15, 2025

CVE-2025-65431

0 CVSS Score Info
Export CVE-2025-65431 Data:
Share:
Link copied!

Description

An issue was discovered in allauth-django before 65.13.0. Both Okta and NetIQ were using preferred_username as the identifier for third-party provider accounts. That value may be mutable and should therefore be avoided for authorization decisions. The providers are now using sub instead.