Executive brief
A security issue was identified in django-allauth, a popular authentication package for Django websites. When using Okta or NetIQ for logins, the system relied on usernames that could be changed by users rather than permanent, unique IDs. This could potentially allow an attacker to gain unauthorized access to another user's account if they are able to claim a previously used or modified username.
Technical details
The Okta and NetIQ provider implementations in django-allauth prior to version 65.13.0 used the 'preferred_username' field as the unique identifier for third-party accounts. Because this field is mutable in some identity provider configurations, it does not meet the requirements for a stable unique identifier. An attacker with the ability to change their username on the identity provider side could potentially link their social account to a different local user account. The fix migrates these providers to use the 'sub' (subject) claim, which is an immutable identifier. Users upgrading to 65.13.0 may need to manually migrate existing SocialAccount records to prevent account linkage issues.
Affected products
- allauth django-allauth < 65.13.0
Timeline
- 2025-10-31: patched: Version 65.13.0 released with fix
- 2025-12-15: disclosed: CVE-2025-65431 published
- 2025-12-15: advisory: GitHub Advisory GHSA-8m3c-c723-h4p4 published