auth has 3 CVEs on record. 3 were published in the last 90 days. The busiest recent month was July 2026 with 3. The median CVSS is 7.2 (high), with 1 rated critical.
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.2
- Publish → KEV
- —
- Last 90 days
- 3 prev 0
3
Total CVEs
1
Critical
0
CISA KEV
0
Exploited
Worst active — by depth score
GHSA-7rqj-j65f-68whCriticalAuth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass52GHSA-xmf8-cvqr-rfgjHigh· 7.5Auth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers41GHSA-x445-f3h2-j279Medium· 6.8Auth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them37
auth vulnerabilities
CVEs affecting auth, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
GHSA-x445-f3h2-j279Medium· 6.8Auth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them
Auth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them
▾ Sunlitauth · @auth/corevia GHSA
GHSA-7rqj-j65f-68whCriticalAuth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass
Auth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass
▾ Midnightauth · @auth/corevia GHSA
GHSA-xmf8-cvqr-rfgjHigh· 7.5Auth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers
Auth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers
▾ Twilightauth · @auth/corevia GHSA