CVE Tools

Next-auth

19 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Next-auth, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

Next-auth CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Next-auth CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-101
2025-110
2025-120
2026-010
2026-020
2026-030
2026-040
2026-050
2026-060
2026-074
2026-084
2026-090

Severity

How the 19 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical18%
  • High433%
  • Medium650%
  • Low18%

Latest CVEs

The 15 most recently published vulnerabilities affecting Next-auth.

  1. CVE-2026-73421NextAuth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error)—
  2. CVE-2026-73420NextAuth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass—
  3. CVE-2026-73419NextAuth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them6.8
  4. CVE-2026-73418NextAuth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers7.5
  5. GHSA-8fpg-xm3f-6cx3Auth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error)—
  6. GHSA-xmf8-cvqr-rfgjAuth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers—
  7. GHSA-7rqj-j65f-68whAuth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass—
  8. GHSA-x445-f3h2-j279Auth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them—
  9. GHSA-5jpx-9hw9-2fx4NextAuthjs Email misdelivery Vulnerability—
  10. CVE-2023-48309next-auth vulnerable to possible user mocking that bypasses basic authentication5.3
  11. CVE-2023-27490Missing proper state, nonce and PKCE checks for OAuth authentication in next-auth8.1
  12. CVE-2022-39263NextAuth.js Upstash Adapter missing token verification6.8
  13. CVE-2022-35924Verification requests (magic link) sent to unwanted emails9.1
  14. CVE-2022-31186Leakage of excessive information into log in next-auth3.3
  15. CVE-2022-31127Improper handling of email input in next-auth7.1

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store