PYSEC-2026-1931
social-auth-app-django affected by Improper Handling of Case Sensitivity
Quick fix
PYSEC-2026-1931 — social-auth-app-django: upgrade to the fixed version with the command below.
pip install --upgrade 'social-auth-app-django>=5.4.1'Details
### Impact Due to default case-insensitive collation in MySQL or MariaDB databases, third-party authentication user IDs are not case-sensitive and could cause different IDs to match.
### Patches This issue has been addressed by https://github.com/python-social-auth/social-app-django/pull/566 and fix released in 5.4.1.
### Workarounds An immediate workaround would be to change collation of the affected field:
```mysql ALTER TABLE `social_auth_usersocialauth` MODIFY `uid` varchar(255) COLLATE `utf8_bin`; ```
### References This issue was discovered by folks at https://opencraft.com/.
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 5.4.1pip install --upgrade 'social-auth-app-django>=5.4.1'References
- https://github.com/python-social-auth/social-app-django/security/advisories/GHSA-2gr8-3wc7-xhj3[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2024-32879[ADVISORY]
- https://github.com/python-social-auth/social-app-django/pull/566[WEB]
- https://github.com/python-social-auth/social-app-django/commit/31c3e0c7edb187004d8abbde7e9c4f7ef9098138[WEB]
- https://github.com/python-social-auth/social-app-django[PACKAGE]
- https://pypi.org/project/social-auth-app-django[PACKAGE]
- https://github.com/advisories/GHSA-2gr8-3wc7-xhj3[ADVISORY]