next-auth vulnerabilities
CVEs whose affected-version data names the next-auth package (npm). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
5 CVEsRSS
CVE-2026-73419Medium· 6.8NextAuth.js provides authentication for Next.js
NextAuth.js provides authentication for Next.js. Prior to@auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, Auth.js stores the OAuth/OIDC anti-CSRF checks state, nonce, and the PKCE verifier in global cookies that are not bound t…
GHSA-x445-f3h2-j279Medium· 6.8Auth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them
Auth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them
GHSA-7rqj-j65f-68whCriticalAuth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass
Auth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass
GHSA-xmf8-cvqr-rfgjHigh· 7.5Auth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers
Auth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers
GHSA-8fpg-xm3f-6cx3CriticalAuth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error)
Auth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error)