Bug 2540600 (CVE-2026-57178) - CVE-2026-57178 social-auth-core: social-auth-core: Authentication bypass via missing signature verification in VK App backend
Summary: CVE-2026-57178 social-auth-core: social-auth-core: Authentication bypass via ...
Keywords:
Status: NEW
Alias: CVE-2026-57178
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-24 17:33 UTC by OSIDB Bzimport
Modified: 2026-09-29 08:06 UTC (History)
12 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-24 17:33:17 UTC
Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the `vk-app` backend accepted VK application callback data without verifying the callback signature when the `auth_key` parameter was omitted. Applications using this backend could treat unsigned attacker-controlled data as a verified VK identity. An attacker could choose callback fields such as `viewer_id`, `access_token`, `api_id`, and `api_result`, potentially allowing authentication as an arbitrary VK user ID. The issue affects only applications using the `vk-app` backend. The issue has been fixed in version 5.0.0 by requiring `auth_key` to be present and valid before callback data is trusted.


Note You need to log in before you can comment on or make changes to this bug.