When using affected versions of the Next.js SDK, simultaneous requests on the same client may result in improper lookups in the TokenRequestCache for the request results.
You are affected if you meet the following preconditions: - Applications using the auth0/nextjs-auth0 SDK with a singleton client instance, versions 4.11.0, 4.11.1, and 4.12.0.
Auth0/nextjs-auth0 v4.11.0, v4.11.1, and v4.12.0.
Upgrade Auth0/nextjs-auth0 version to v4.11.2 or v4.12.1
Okta would like to thank Joshua Rogers (MegaManSec) for their discovery and responsible disclosure.
{
"cwe_ids": [
"CWE-863"
],
"severity": "MODERATE",
"github_reviewed_at": "2025-12-10T21:31:24Z",
"nvd_published_at": "2025-12-10T23:15:48Z",
"github_reviewed": true
}