Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-xmf8-cvqr-rfgj
  • npm/@auth/core
  • npm/next-auth
Auth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers 23 Jul
  • Fix available
  • Severity - 7.5 (High)
GHSA-7rqj-j65f-68wh
  • npm/@auth/core
  • npm/next-auth
Auth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass 23 Jul
  • Fix available
  • Severity - 9.1 (Critical)
GHSA-x445-f3h2-j279
  • npm/@auth/core
  • npm/next-auth
Auth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them 23 Jul
  • Fix available
  • Severity - 6.8 (Medium)