Next-auth
This hub aggregates every CVE we track for Next-auth, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
12
CVEs tracked
1
Critical
4
High
0
In CISA KEV
Severity distribution
MEDIUM6HIGH4LOW1CRITICAL1
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2
0
2024-102026-09
Latest CVEs
The 12 most recently published vulnerabilities affecting Next-auth.
- CVE-2026-73419NextAuth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them6.8
- CVE-2026-73418NextAuth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers7.5
- CVE-2023-48309next-auth vulnerable to possible user mocking that bypasses basic authentication5.3
- CVE-2023-27490Missing proper state, nonce and PKCE checks for OAuth authentication in next-auth8.1
- CVE-2022-39263NextAuth.js Upstash Adapter missing token verification6.8
- CVE-2022-35924Verification requests (magic link) sent to unwanted emails9.1
- CVE-2022-31186Leakage of excessive information into log in next-auth3.3
- CVE-2022-31127Improper handling of email input in next-auth7.1
- CVE-2022-31093Improper Handling of `callbackUrl` parameter in next-auth7.5
- CVE-2022-29214URL Redirection to Untrusted Site ('Open Redirect') in next-auth6.1
- CVE-2022-24858Default redirect callback vulnerable to open redirects6.1
- CVE-2021-21310Token verification bug in next-auth6.1
Product normalization is registry-driven with AI assist and human review. How it works