Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2198788
AlmaLinux
5919
Alpaquita
15755
Alpine
4608
Android
3674
Azure Linux
17638
BellSoft Hardened Containers
746
Bitnami
9290
Chainguard
1023665
CleanStart
3591
CRAN
14
crates.io
2732
Debian
68356
Echo
6721
GHC
3
GIT
108079
GitHub Actions
55
Go
9203
Hackage
32
Hex
361
Julia
1713
Linux
29974
Mageia
6227
Maven
7040
MinimOS
144358
npm
228732
NuGet
1869
opam
29
openEuler
8800
openSUSE
14455
OSS-Fuzz
4013
Packagist
7095
Pub
11
PyPI
25166
Red Hat
23331
Rocky Linux
4295
Root
19534
RubyGems
5326
SUSE
23168
SwiftURL
60
TuxCare
9498
Ubuntu
65370
VSCode
21
Wolfi
288261
ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-8fpg-xm3f-6cx3
npm/next-auth
Auth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error)
23 Jul
Fix available
Severity - 9.1 (Critical)
GHSA-xmf8-cvqr-rfgj
npm/@auth/core
npm/next-auth
Auth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers
23 Jul
Fix available
Severity - 7.5 (High)
GHSA-7rqj-j65f-68wh
npm/@auth/core
npm/next-auth
Auth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass
23 Jul
Fix available
Severity - 9.1 (Critical)
GHSA-x445-f3h2-j279
npm/@auth/core
npm/next-auth
Auth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them
23 Jul
Fix available
Severity - 6.8 (Medium)
GHSA-5jpx-9hw9-2fx4
npm/next-auth
NextAuthjs Email misdelivery Vulnerability
29 Oct 2025
Fix available
Severity - 6.9 (Medium)
MAL-2025-3794
npm/next-auth-core
Malicious code in next-auth-core (npm)
14 May 2025
No fix available
GHSA-v64w-49xw-qq89
npm/next-auth
Possible user mocking that bypasses basic authentication
20 Nov 2023
Fix available
Severity - 5.3 (Medium)
GHSA-7r7x-4c4q-c4qf
npm/next-auth
Missing proper state, nonce and PKCE checks for OAuth authentication
13 Mar 2023
Fix available
Severity - 8.1 (High)
GHSA-p6mm-27gq-9v3p
npm/next-auth
next-auth before v4.10.2 and v3.29.9 leaks excessive information into log
06 Aug 2022
Fix available
Severity - 3.3 (Low)
GHSA-xv97-c62v-4587
npm/next-auth
NextAuth.js before 4.10.3 and 3.29.10 sending verification requests (magic link) to unwanted emails
02 Aug 2022
Fix available
Severity - 9.1 (Critical)
GHSA-pgjx-7f9g-9463
npm/next-auth
Improper handling of email input
06 Jul 2022
Fix available
Severity - 7.1 (High)
GHSA-g5fm-jp9v-2432
npm/next-auth
Improper Handling of `callbackUrl` parameter in next-auth
21 Jun 2022
Fix available
Severity - 7.5 (High)
GHSA-q2mx-j4x2-2h74
npm/next-auth
URL Redirection to Untrusted Site ('Open Redirect') in next-auth
24 May 2022
Fix available
Severity - 6.1 (Medium)
GHSA-f9wg-5f46-cjmw
npm/next-auth
NextAuth.js default redirect callback vulnerable to open redirects
22 Apr 2022
Fix available
Severity - 6.1 (Medium)
GHSA-pg53-56cg-4m8q
npm/next-auth
Token verification bug in next-auth
11 Feb 2021
Fix available
npm - OSV