Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-4168
  • PyPI/social-auth-core
social-auth-core has a Session Fixation issue 4 days ago
  • Fix available
  • Severity - 4.2 (Medium)
PYSEC-2026-4165
  • PyPI/social-auth-core
social-auth-core: VK App backend accepts unsigned callback data when auth_key is missing 4 days ago
  • Fix available
  • Severity - 7.4 (High)
PYSEC-2026-4169
  • PyPI/social-auth-core
social-auth-core has Login CSRF via Missing State Parameter in LoginRadius Backend 4 days ago
  • Fix available
  • Severity - 4.3 (Medium)
PYSEC-2026-4166
  • PyPI/social-auth-core
social-auth-core Vulnerable to Account Takeover via Identity Binding Flaw in Vend Backend 4 days ago
  • Fix available
  • Severity - 6.8 (Medium)
PYSEC-2026-4167
  • PyPI/social-auth-core
social-auth-core has an Improper Authentication issue 4 days ago
  • Fix available
  • Severity - 6.4 (Medium)
GHSA-vqg6-3fw6-j9jg
  • PyPI/social-auth-core
social-auth-core has a Session Fixation issue 24 Sep
  • Fix available
  • Severity - 4.2 (Medium)
GHSA-3c93-f73f-qc9h
  • PyPI/social-auth-core
social-auth-core: VK App backend accepts unsigned callback data when auth_key is missing 24 Sep
  • Fix available
  • Severity - 7.4 (High)
GHSA-x7qq-23vw-7pfg
  • PyPI/social-auth-core
social-auth-core has Login CSRF via Missing State Parameter in LoginRadius Backend 24 Sep
  • Fix available
  • Severity - 4.3 (Medium)
GHSA-fp7w-m676-w7gc
  • PyPI/social-auth-core
social-auth-core Vulnerable to Account Takeover via Identity Binding Flaw in Vend Backend 24 Sep
  • Fix available
  • Severity - 6.8 (Medium)
GHSA-vq6g-g6c7-5f2j
  • PyPI/social-auth-core
social-auth-core has an Improper Authentication issue 24 Sep
  • Fix available
  • Severity - 6.4 (Medium)
MAL-2026-15577
  • PyPI/auth-app-streamlit
Malicious code in auth-app-streamlit (PyPI) 30 Aug
  • No fix available
MAL-2026-10919
  • PyPI/ml-core-airflow-auth
Malicious code in ml-core-airflow-auth (PyPI) 20 Jul
  • No fix available
PYSEC-2026-1932
  • PyPI/social-auth-app-django
Python Social Auth - Django has unsafe account association 07 Jul
  • Fix available
  • Severity - 6.3 (Medium)
MAL-2026-7452
  • PyPI/cyberday26szymon-auth
Malicious code in cyberday26szymon-auth (PyPI) 07 Jul
  • No fix available
PYSEC-2026-1931
  • PyPI/social-auth-app-django
social-auth-app-django affected by Improper Handling of Case Sensitivity 07 Jul
  • Fix available
  • Severity - 4.9 (Medium)
MAL-2026-6230
  • PyPI/django-auth-middleware-plus
Malicious code in django-auth-middleware-plus (PyPI) 19 Jun
  • No fix available