Overview In Auth0 Next.js SDK versions 4.0.1 to 4.6.0, __session cookies set by auth0.middleware may be cached by CDNs due to missing Cache-Control headers.
Am I Affected? You are affected by this vulnerability if you meet the following preconditions:
Fix Upgrade auth0/nextjs-auth0 to v4.6.1.
{
"cwe_ids": [
"CWE-525"
],
"github_reviewed": true,
"github_reviewed_at": "2025-06-04T21:24:52Z",
"nvd_published_at": "2025-06-04T21:15:40Z",
"severity": "HIGH"
}