CVE-2026-57175
Last modified
CVE-2026-57175 is a medium-severity vulnerability rated 6.4/10 on the CVSS scale. Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the SAML backend accepted SAML responses on the Assertion Consumer Service endpoint without verifying that they matched a previously issued `AuthnRequest`.
Description
Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the SAML backend accepted SAML responses on the Assertion Consumer Service endpoint without verifying that they matched a previously issued `AuthnRequest`. Applications using SAML account association could allow an attacker with a valid account on a trusted IdP to link the attacker's SAML identity to a logged-in victim's local account. The attacker could then authenticate through SAML and gain access to the victim's account. The issue affects applications using the SAML backend together with authenticated account association. The issue has been fixed in version 5.0.0 by validating SAML responses against stored `AuthnRequest` IDs.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| python-social-auth | social-core | < 5.0.0 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-57175?
How severe is CVE-2026-57175?
How do I fix CVE-2026-57175?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-57168Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMB…
- CVE-2026-5717The VI: Include Post By plugin for WordPress is vulnerable t…6.4
- CVE-2026-57170Compliance-trestle (Trestle) is a Python SDK and command-lin…7.8
- CVE-2026-57171Compliance-trestle (Trestle) is a Python SDK and command-lin…7.7
- CVE-2026-57172DataEase is an open source data visualization and analysis t…8.3
- CVE-2026-57173vLLM is an inference and serving engine for large language m…6.5
- CVE-2026-57176Python Social Auth is a social authentication/registration m…6.8
- CVE-2026-57177Python Social Auth is a social authentication/registration m…4.3
- CVE-2026-57178Python Social Auth is a social authentication/registration m…7.4
- CVE-2026-57179Python Social Auth is a social authentication/registration m…4.2
- CVE-2026-5718The Drag and Drop Multiple File Upload for Contact Form 7 pl…8.1
- CVE-2026-5719A flaw has been found in itsourcecode Construction Managemen…6.3
Are you affected by CVE-2026-57175?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
