Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-8fpg-xm3f-6cx3
  • npm/next-auth
Auth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error) 23 Jul
  • Fix available
  • Severity - 9.1 (Critical)
GHSA-xmf8-cvqr-rfgj
  • npm/@auth/core
  • npm/next-auth
Auth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers 23 Jul
  • Fix available
  • Severity - 7.5 (High)
GHSA-7rqj-j65f-68wh
  • npm/@auth/core
  • npm/next-auth
Auth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass 23 Jul
  • Fix available
  • Severity - 9.1 (Critical)
GHSA-x445-f3h2-j279
  • npm/@auth/core
  • npm/next-auth
Auth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them 23 Jul
  • Fix available
  • Severity - 6.8 (Medium)
GHSA-5jpx-9hw9-2fx4
  • npm/next-auth
NextAuthjs Email misdelivery Vulnerability 29 Oct 2025
  • Fix available
  • Severity - 6.9 (Medium)
MAL-2025-3794
  • npm/next-auth-core
Malicious code in next-auth-core (npm) 14 May 2025
  • No fix available
GHSA-v64w-49xw-qq89
  • npm/next-auth
Possible user mocking that bypasses basic authentication 20 Nov 2023
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-7r7x-4c4q-c4qf
  • npm/next-auth
Missing proper state, nonce and PKCE checks for OAuth authentication 13 Mar 2023
  • Fix available
  • Severity - 8.1 (High)
GHSA-p6mm-27gq-9v3p
  • npm/next-auth
next-auth before v4.10.2 and v3.29.9 leaks excessive information into log 06 Aug 2022
  • Fix available
  • Severity - 3.3 (Low)
GHSA-xv97-c62v-4587
  • npm/next-auth
NextAuth.js before 4.10.3 and 3.29.10 sending verification requests (magic link) to unwanted emails 02 Aug 2022
  • Fix available
  • Severity - 9.1 (Critical)
GHSA-pgjx-7f9g-9463
  • npm/next-auth
Improper handling of email input 06 Jul 2022
  • Fix available
  • Severity - 7.1 (High)
GHSA-g5fm-jp9v-2432
  • npm/next-auth
Improper Handling of `callbackUrl` parameter in next-auth 21 Jun 2022
  • Fix available
  • Severity - 7.5 (High)
GHSA-q2mx-j4x2-2h74
  • npm/next-auth
URL Redirection to Untrusted Site ('Open Redirect') in next-auth 24 May 2022
  • Fix available
  • Severity - 6.1 (Medium)
GHSA-f9wg-5f46-cjmw
  • npm/next-auth
NextAuth.js default redirect callback vulnerable to open redirects 22 Apr 2022
  • Fix available
  • Severity - 6.1 (Medium)
GHSA-pg53-56cg-4m8q
  • npm/next-auth
Token verification bug in next-auth 11 Feb 2021
  • Fix available