Junglewise Threat Intelligence

CVE-2024-32879: PYSEC-2026-1931 - social-auth-app-django affected by Improper Handling of Case Sensitivity

CVE-2024-32879 · Severity: low · CVSS 3.1 · Published 2026-07-07

Vendors: Python-Social-Auth, PyPI.

Executive brief

social-auth-app-django is a Django library that integrates third-party authentication providers (like OAuth, SAML, etc.) with Django applications. When deployed with MySQL or MariaDB databases using default case-insensitive collation, the library fails to properly validate user IDs during authentication, allowing different user accounts to be treated as identical if they differ only in case. This could permit an attacker with a third-party account to gain unauthorized access to another user's account.

Technical details

The vulnerability stems from improper handling of case sensitivity in the user ID (uid) field stored in the social_auth_usersocialauth table. When MySQL or MariaDB databases use default case-insensitive collation, a uid value of "UserID" and "userid" are treated as the same record during authentication lookups, violating the authentication algorithm's assumption that user IDs are case-sensitive. An attacker can exploit this by controlling a third-party authentication provider account whose ID differs only in case from a target user, then authentication will incorrectly match to the existing account. The issue affects all versions prior to 5.4.1; patches are available via PR #566. A temporary workaround involves manually altering the table collation to utf8_bin on affected databases.

Affected products

  • python-social-auth social-auth-app-django <5.4.1

Timeline

  • 2024-04-24: disclosed
  • 2024-04-24: patched: version 5.4.1 released

References

Related threats