Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
ECHO-2dd4-1209-8fa6
  • Echo:npm/next-auth
See record for full details 28 Sep
  • Fix available
ECHO-4bf4-a83a-db7c
  • Echo:npm/next-auth
See record for full details 28 Sep
  • Fix available
ECHO-bdc4-d206-ec90
  • Echo:npm/next-auth
See record for full details 28 Sep
  • Fix available
CVE-2026-73421
  • github.com/nextauthjs/next-auth
NextAuth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error) 13 Aug
  • Fix available
  • Severity - 9.1 (Critical)
CVE-2026-73420
  • github.com/nextauthjs/next-auth
NextAuth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass 13 Aug
  • Fix available
  • Severity - 9.1 (Critical)
CVE-2026-73419
  • github.com/nextauthjs/next-auth
NextAuth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them 12 Aug
  • Fix available
  • Severity - 6.8 (Medium)
CVE-2026-73418
  • github.com/nextauthjs/next-auth
NextAuth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers 12 Aug
  • Fix available
  • Severity - 7.5 (High)
GHSA-8fpg-xm3f-6cx3
  • npm/next-auth
Auth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error) 23 Jul
  • Fix available
  • Severity - 9.1 (Critical)
GHSA-xmf8-cvqr-rfgj
  • npm/@auth/core
  • npm/next-auth
Auth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers 23 Jul
  • Fix available
  • Severity - 7.5 (High)
GHSA-7rqj-j65f-68wh
  • npm/@auth/core
  • npm/next-auth
Auth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass 23 Jul
  • Fix available
  • Severity - 9.1 (Critical)
GHSA-x445-f3h2-j279
  • npm/@auth/core
  • npm/next-auth
Auth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them 23 Jul
  • Fix available
  • Severity - 6.8 (Medium)
GHSA-5jpx-9hw9-2fx4
  • npm/next-auth
NextAuthjs Email misdelivery Vulnerability 29 Oct 2025
  • Fix available
  • Severity - 6.9 (Medium)
MAL-2025-3794
  • npm/next-auth-core
Malicious code in next-auth-core (npm) 14 May 2025
  • No fix available
GHSA-v64w-49xw-qq89
  • npm/next-auth
Possible user mocking that bypasses basic authentication 20 Nov 2023
  • Fix available
  • Severity - 5.3 (Medium)
CVE-2023-48309
  • github.com/nextauthjs/next-auth
next-auth vulnerable to possible user mocking that bypasses basic authentication 20 Nov 2023
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-7r7x-4c4q-c4qf
  • npm/next-auth
Missing proper state, nonce and PKCE checks for OAuth authentication 13 Mar 2023
  • Fix available
  • Severity - 8.1 (High)