GHSA-wcgj-f865-c7j7

Suggest an improvement
Source
https://github.com/advisories/GHSA-wcgj-f865-c7j7
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/12/GHSA-wcgj-f865-c7j7/GHSA-wcgj-f865-c7j7.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-wcgj-f865-c7j7
Aliases
Published
2025-12-10T21:31:24Z
Modified
2025-12-11T16:22:30.784670Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:N CVSS Calculator
Summary
Improper Request Caching Lookup in the Auth0 Next.js SDK
Details

Description

When using affected versions of the Next.js SDK, simultaneous requests on the same client may result in improper lookups in the TokenRequestCache for the request results.

Am I Affected?

You are affected if you meet the following preconditions: - Applications using the auth0/nextjs-auth0 SDK with a singleton client instance, versions 4.11.0, 4.11.1, and 4.12.0.

Affected product and versions

Auth0/nextjs-auth0 v4.11.0, v4.11.1, and v4.12.0.

Resolution

Upgrade Auth0/nextjs-auth0 version to v4.11.2 or v4.12.1

Acknowledgements

Okta would like to thank Joshua Rogers (MegaManSec) for their discovery and responsible disclosure.

Database specific
{
    "cwe_ids": [
        "CWE-863"
    ],
    "severity": "MODERATE",
    "github_reviewed_at": "2025-12-10T21:31:24Z",
    "nvd_published_at": "2025-12-10T23:15:48Z",
    "github_reviewed": true
}
References

Affected packages

npm / @auth0/nextjs-auth0

Package

Name
@auth0/nextjs-auth0
View open source insights on deps.dev
Purl
pkg:npm/%40auth0/nextjs-auth0

Affected ranges

Type
SEMVER
Events
Introduced
4.11.0
Fixed
4.11.2

npm / @auth0/nextjs-auth0

Package

Name
@auth0/nextjs-auth0
View open source insights on deps.dev
Purl
pkg:npm/%40auth0/nextjs-auth0

Affected ranges

Type
SEMVER
Events
Introduced
4.12.0
Fixed
4.12.1