Package: release.debian.org
Severity: normal
Tags: bookworm
X-Debbugs-Cc: [email protected]
Control: affects -1 + src:django-allauth
User: [email protected]
Usertags: pu

Hello,

[ Reason ]
django-allauth has seen three CVEs reported, of which two I was able to
find in the version released in stable.

I cherry-picked the commits from upstream and built a new version

[ Impact ]
These CVEs are not major, if you believe these changes should not hit
stable it is fine with me.

[ Tests ]
Build and autopkgtest tests do cover the changed code

[ Risks ]
Changes are rather trivial.

[ Checklist ]
  [x] *all* changes are documented in the d/changelog
  [x] I reviewed all changes and I approve them
  [x] attach debdiff against the package in (old)stable
  [x] the issue is verified as fixed in unstable

[ Changes ]
  * d/p/0004: fix(saml): prevent open redirect with IdP initiated SSO
    (Closes: CVE-2026-27982, #1130044)

    This change merely verifies that an url complies with the checks
    done with is_safe_url, as defined in the DefaultAdapter in
    allauth/account/adapter.py
  * d/p/0005: fix(socialaccount): use ``sub`` in Okta/NetIQ
    (Closes: CVE-2025-65431; #1123085)

    This change moves from a mutable field to a non-mutable one
    for the identifier used for the third party account in NetIQ and
    Okta, which means that as soon as the user would change their
    preferred_username, it would induce the creation of another account
    upon relogin.
diff -Nru django-allauth-65.0.2/debian/changelog 
django-allauth-65.0.2/debian/changelog
--- django-allauth-65.0.2/debian/changelog      2024-10-20 15:36:10.000000000 
+0200
+++ django-allauth-65.0.2/debian/changelog      2026-08-28 18:17:15.000000000 
+0200
@@ -1,3 +1,14 @@
+django-allauth (65.0.2-1+deb13u1) trixie; urgency=medium
+
+  * d/p/0004: fix(saml): prevent open redirect with IdP initiated SSO
+    (Closes: CVE-2026-27982, #1130044)
+  * d/p/0005: fix(socialaccount): use ``sub`` in Okta/NetIQ
+    (Closes: CVE-2025-65431; #1123085)
+  * Note: the code vulnerable to CVE-2025-65430 does not seem to exist in
+    65.0.2 and therefore no patch is provided
+
+ -- Pierre-Elliott Bécue <[email protected]>  Fri, 28 Aug 2026 18:17:15 +0200
+
 django-allauth (65.0.2-1) unstable; urgency=medium
 
   * New upstream release 65.0.2
diff -Nru 
django-allauth-65.0.2/debian/patches/0003-Fix-testing-settings-relying-on-MFA_PASSKEY_SIGNUP_E.patch
 
django-allauth-65.0.2/debian/patches/0003-Fix-testing-settings-relying-on-MFA_PASSKEY_SIGNUP_E.patch
--- 
django-allauth-65.0.2/debian/patches/0003-Fix-testing-settings-relying-on-MFA_PASSKEY_SIGNUP_E.patch
        2024-10-20 15:36:10.000000000 +0200
+++ 
django-allauth-65.0.2/debian/patches/0003-Fix-testing-settings-relying-on-MFA_PASSKEY_SIGNUP_E.patch
        2026-08-28 18:15:30.000000000 +0200
@@ -1,8 +1,8 @@
 From: =?utf-8?q?Pierre-Elliott_B=C3=A9cue?= <[email protected]>
 Date: Sun, 20 Oct 2024 14:53:59 +0200
 Subject: Fix testing settings relying on MFA_PASSKEY_SIGNUP_ENABLED
-Forwarded: https://codeberg.org/allauth/django-allauth/pulls/4150
 
+Forwarded: https://codeberg.org/allauth/django-allauth/pulls/4150
 ---
  allauth/mfa/checks.py               | 2 +-
  tests/headless_only/settings.py     | 3 +++
diff -Nru 
django-allauth-65.0.2/debian/patches/0004-fix-saml-prevent-open-redirect-with-IdP-initiated-SS.patch
 
django-allauth-65.0.2/debian/patches/0004-fix-saml-prevent-open-redirect-with-IdP-initiated-SS.patch
--- 
django-allauth-65.0.2/debian/patches/0004-fix-saml-prevent-open-redirect-with-IdP-initiated-SS.patch
        1970-01-01 01:00:00.000000000 +0100
+++ 
django-allauth-65.0.2/debian/patches/0004-fix-saml-prevent-open-redirect-with-IdP-initiated-SS.patch
        2026-08-28 18:15:30.000000000 +0200
@@ -0,0 +1,30 @@
+From: Raymond Penners <[email protected]>
+Date: Sat, 7 Feb 2026 23:27:26 +0100
+Subject: fix(saml): prevent open redirect with IdP initiated SSO
+
+---
+ allauth/socialaccount/providers/saml/utils.py | 4 +++-
+ 1 file changed, 3 insertions(+), 1 deletion(-)
+
+diff --git a/allauth/socialaccount/providers/saml/utils.py 
b/allauth/socialaccount/providers/saml/utils.py
+index c8a3d16..dc49b67 100644
+--- a/allauth/socialaccount/providers/saml/utils.py
++++ b/allauth/socialaccount/providers/saml/utils.py
+@@ -10,6 +10,7 @@ from onelogin.saml2.auth import OneLogin_Saml2_Auth
+ from onelogin.saml2.constants import OneLogin_Saml2_Constants
+ from onelogin.saml2.idp_metadata_parser import 
OneLogin_Saml2_IdPMetadataParser
+ 
++from allauth.account.adapter import get_adapter as get_account_adapter
+ from allauth.socialaccount.adapter import get_adapter
+ from allauth.socialaccount.models import SocialApp
+ from allauth.socialaccount.providers.saml.provider import SAMLProvider
+@@ -164,7 +165,8 @@ def decode_relay_state(relay_state):
+     if relay_state:
+         parts = urlparse(relay_state)
+         if parts.scheme or parts.netloc or (parts.path and 
parts.path.startswith("/")):
+-            next_url = relay_state
++            if get_account_adapter().is_safe_url(relay_state):
++                next_url = relay_state
+     return next_url
+ 
+ 
diff -Nru 
django-allauth-65.0.2/debian/patches/0005-fix-socialaccount-use-sub-in-Okta-NetIQ.patch
 
django-allauth-65.0.2/debian/patches/0005-fix-socialaccount-use-sub-in-Okta-NetIQ.patch
--- 
django-allauth-65.0.2/debian/patches/0005-fix-socialaccount-use-sub-in-Okta-NetIQ.patch
     1970-01-01 01:00:00.000000000 +0100
+++ 
django-allauth-65.0.2/debian/patches/0005-fix-socialaccount-use-sub-in-Okta-NetIQ.patch
     2026-08-28 18:15:30.000000000 +0200
@@ -0,0 +1,37 @@
+From: Raymond Penners <[email protected]>
+Date: Wed, 29 Oct 2025 22:07:53 +0100
+Subject: fix(socialaccount): use ``sub`` in Okta/NetIQ
+
+---
+ allauth/socialaccount/providers/netiq/provider.py | 3 ++-
+ allauth/socialaccount/providers/okta/provider.py  | 3 ++-
+ 2 files changed, 4 insertions(+), 2 deletions(-)
+
+diff --git a/allauth/socialaccount/providers/netiq/provider.py 
b/allauth/socialaccount/providers/netiq/provider.py
+index f85fa15..c4fa064 100644
+--- a/allauth/socialaccount/providers/netiq/provider.py
++++ b/allauth/socialaccount/providers/netiq/provider.py
+@@ -17,7 +17,8 @@ class NetIQProvider(OAuth2Provider):
+         return ["openid", "profile", "email"]
+ 
+     def extract_uid(self, data):
+-        return str(data["preferred_username"])
++        uid_field = self.app.settings.get("uid_field", "sub")
++        return str(data[uid_field])
+ 
+     def extract_extra_data(self, data):
+         return data
+diff --git a/allauth/socialaccount/providers/okta/provider.py 
b/allauth/socialaccount/providers/okta/provider.py
+index bdb00ec..0b6ab5e 100644
+--- a/allauth/socialaccount/providers/okta/provider.py
++++ b/allauth/socialaccount/providers/okta/provider.py
+@@ -18,7 +18,8 @@ class OktaProvider(OAuth2Provider):
+         return ["openid", "profile", "email", "offline_access"]
+ 
+     def extract_uid(self, data):
+-        return str(data["preferred_username"])
++        uid_field = self.app.settings.get("uid_field", "sub")
++        return str(data[uid_field])
+ 
+     def extract_extra_data(self, data):
+         return data
diff -Nru django-allauth-65.0.2/debian/patches/series 
django-allauth-65.0.2/debian/patches/series
--- django-allauth-65.0.2/debian/patches/series 2024-10-20 15:36:10.000000000 
+0200
+++ django-allauth-65.0.2/debian/patches/series 2026-08-28 18:15:30.000000000 
+0200
@@ -1,3 +1,5 @@
 0001-Remove-all-privacy-breack-links-from-documentation.patch
 0002-Fixes-wrongly-encoded-characters-in-some-.po-files.patch
 0003-Fix-testing-settings-relying-on-MFA_PASSKEY_SIGNUP_E.patch
+0004-fix-saml-prevent-open-redirect-with-IdP-initiated-SS.patch
+0005-fix-socialaccount-use-sub-in-Okta-NetIQ.patch

Reply via email to