VDB
Sign up
—

PYSEC-2026-1932

Python Social Auth - Django has unsafe account association

Quick fix

PYSEC-2026-1932 — social-auth-app-django: upgrade to the fixed version with the command below.

pip install --upgrade 'social-auth-app-django>=5.6.0'

Details

### Impact

Upon authentication, the user could be associated by e-mail even if the `associate_by_email` pipeline was not included. This could lead to account compromise when a third-party authentication service does not validate provided e-mail addresses or doesn't require unique e-mail addresses.

### Patches

* https://github.com/python-social-auth/social-app-django/pull/803

### Workarounds

Review the authentication service policy on e-mail addresses; many will not allow exploiting this vulnerability.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/social-auth-app-django
Introduced in: 0Fixed in: 5.6.0
Fixpip install --upgrade 'social-auth-app-django>=5.6.0'

References