Hi,
The following vulnerability was published for django-allauth.
CVE-2026-97764[0]:
| django-allauth before 65.19.4 does not have the expected limits on
| failed login attempts because, in some common configurations, an
| attacker can leverage the handling of diacritics (e.g., accents) for
| a higher effective limit.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-97764
https://www.cve.org/CVERecord?id=CVE-2026-97764
[1] https://codeberg.org/allauth/django-allauth/commit/4379e7931fe7572aacc4f3b4b5f2298d5f3ecc96
[2] https://codeberg.org/allauth/django-allauth/commit/4e252aa2be7cef5d72d78049d6fb07cb27a89c83
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore