auth0
Security Productscommercial
Latest CVEs
The 15 most recently published vulnerabilities affecting auth0.
- CVE-2026-50157Auth0 Symfony: Bearer Token Accepted via URL Query Parameter in Auth0 Symfony SDK6.5
- CVE-2026-84685Improper Cache Isolation in auth0/react-native-auth0 SDK Web Platform Credential Management6.5
- CVE-2026-85983Local Privilege Escalation in Auth0 AD/LDAP Connector7.8
- CVE-2026-85982Stored Cross-Site Scripting (XSS) in Auth0 AD/LDAP Connector9.0
- CVE-2026-85981Unauthenticated Localhost Admin Panel in Auth0 AD/LDAP Connector6.7
- CVE-2026-42280Improper Permission Checking in Auth.js SDK7.1
- CVE-2026-40155Auth0 Next.js SDK has Improper Proxy Cache Lookup5.4
- CVE-2026-34236Auth0 PHP SDK Insufficient Entropy in Cookie Encryption8.2
- CVE-2025-68129Auth0-PHP SDK has Improper Audience Validation6.8
- CVE-2025-67716Auth0 Next.js SDK has Improper Validation of Query Parameters5.7
- CVE-2025-67490Auth0 Next.js SDK has Improper Request Caching Lookup5.4
- CVE-2025-65945auth0/node-jws improper HMAC signature verification vulnerability7.5
- CVE-2025-58769auth0-PHP: Improper File Type Handling in Bulk User Import3.3
- CVE-2025-48947NextJS-Auth0 SDK Vulnerable to CDN Caching of Session Cookies
- CVE-2025-48951Auth0-PHP SDK Deserialization of Untrusted Data vulnerability