Auth0 has 6 CVEs on record between 2025 and 2026. 5 were published in the last 90 days. The busiest recent month was September 2026 with 5. The median CVSS is 7.1 (high), with 1 rated critical. None have a confirmed exploitation report. Most affected products: Auth0 AD/LDAP Connector (3), node-jws (1), react-native-auth0 (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.1
- Publish → KEV
- —
- Last 90 days
- 5 prev 0
Products
- Auth0 AD/LDAP Connector 3
- node-jws 1
- react-native-auth0 1
- symfony 1
Worst active — by depth score
CVE-2025-65945High· 7.5auth0/node-jws is a JSON Web Signature implementation for Node.js53CVE-2026-85982Critical· 9.0The Auth0 AD/LDAP Connector is vulnerable to stored Cross-Site Scripting (XSS) issues due to improper HTML encoding of data in search results and updater log content displayed in the admin panel50CVE-2026-85983High· 7.8The Auth0 AD/LDAP Connector improperly processes a configuration value during service startup43CVE-2026-85981Medium· 6.7The administrative panel of the Auth0 AD/LDAP Connector (versions 6.5.0 and earlier) listens on the local loopback interface without requiring authentication37CVE-2026-50157Medium· 6.5Auth0 Symfony is a Symfony SDK for Auth0 Authentication and Management APIs36
Auth0 vulnerabilities
CVEs affecting Auth0, newest first. Open any entry for full detail, references, and exploit status.
6 CVEsRSS
CVE-2026-50157Medium· 6.5Auth0 Symfony is a Symfony SDK for Auth0 Authentication and Management APIs
Auth0 Symfony is a Symfony SDK for Auth0 Authentication and Management APIs. From 5.0.0-BETA0 until 5.9.0, the Authorizer::authenticate() and Authorizer::supports() paths in the Authorizer security authenticator may accept OAuth 2.0 bear…
CVE-2026-85983High· 7.8The Auth0 AD/LDAP Connector improperly processes a configuration value during service startup
The Auth0 AD/LDAP Connector improperly processes a configuration value during service startup. This allows a low-privileged user on the host system to modify the connector's configuration. When the service restarts, the modified configur…
CVE-2026-85982Critical· 9.0The Auth0 AD/LDAP Connector is vulnerable to stored Cross-Site Scripting (XSS) issues due to improper HTML encoding of data in search results and updater log content displayed in the admin panel
The Auth0 AD/LDAP Connector is vulnerable to stored Cross-Site Scripting (XSS) issues due to improper HTML encoding of data in search results and updater log content displayed in the admin panel. An authenticated user with privileges to …
CVE-2026-85981Medium· 6.7The administrative panel of the Auth0 AD/LDAP Connector (versions 6.5.0 and earlier) listens on the local loopback interface without requiring authentication
The administrative panel of the Auth0 AD/LDAP Connector (versions 6.5.0 and earlier) listens on the local loopback interface without requiring authentication. This allows a local, low-privileged user or process on the host system to acce…
CVE-2026-84685Medium· 6.5The react-native-auth0 SDK's web platform implementation does not scope its in-memory token cache to individual user sessions when operating in a server-side rendering (SSR) environment where module state persists across HTTP requests
The react-native-auth0 SDK's web platform implementation does not scope its in-memory token cache to individual user sessions when operating in a server-side rendering (SSR) environment where module state persists across HTTP requests. U…
CVE-2025-65945High· 7.5PoCauth0/node-jws is a JSON Web Signature implementation for Node.js
auth0/node-jws is a JSON Web Signature implementation for Node.js. In versions 3.2.2 and earlier and version 4.0.0, auth0/node-jws has an improper signature verification vulnerability when using the HS256 algorithm under specific conditi…