@auth/core vulnerabilities
CVEs whose affected-version data names the @auth/core package (npm). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
GHSA-x445-f3h2-j279Medium· 6.8Auth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them
Auth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them
▾ Sunlitauth · @auth/corevia GHSA
GHSA-7rqj-j65f-68whCriticalAuth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass
Auth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass
▾ Midnightauth · @auth/corevia GHSA
GHSA-xmf8-cvqr-rfgjHigh· 7.5Auth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers
Auth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers
▾ Twilightauth · @auth/corevia GHSA