In applications built with the Auth0 PHP SDK, cookies are encrypted with insufficient entropy, which may result in threat actors brute-forcing the encryption key and forging session cookies.
You are affected if you meet the following preconditions:
Upgrade Auth0/laravel-auth0 to version 7.21.0 or greater.
{
"cwe_ids": [
"CWE-331"
],
"github_reviewed": true,
"github_reviewed_at": "2026-04-03T03:41:04Z",
"nvd_published_at": null,
"severity": "HIGH"
}