Next-auth
19 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Next-auth, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
Next-auth CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 1 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 4 |
| 2026-08 | 4 |
| 2026-09 | 0 |
Severity
How the 19 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical1
- High4
- Medium6
- Low1
Latest CVEs
The 15 most recently published vulnerabilities affecting Next-auth.
- CVE-2026-73421NextAuth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error)—
- CVE-2026-73420NextAuth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass—
- CVE-2026-73419NextAuth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them6.8
- CVE-2026-73418NextAuth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers7.5
- GHSA-8fpg-xm3f-6cx3Auth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error)—
- GHSA-xmf8-cvqr-rfgjAuth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers—
- GHSA-7rqj-j65f-68whAuth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass—
- GHSA-x445-f3h2-j279Auth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them—
- GHSA-5jpx-9hw9-2fx4NextAuthjs Email misdelivery Vulnerability—
- CVE-2023-48309next-auth vulnerable to possible user mocking that bypasses basic authentication5.3
- CVE-2023-27490Missing proper state, nonce and PKCE checks for OAuth authentication in next-auth8.1
- CVE-2022-39263NextAuth.js Upstash Adapter missing token verification6.8
- CVE-2022-35924Verification requests (magic link) sent to unwanted emails9.1
- CVE-2022-31186Leakage of excessive information into log in next-auth3.3
- CVE-2022-31127Improper handling of email input in next-auth7.1
Product grouping is registry-driven, with AI assist and human review. How it works