Security Advisories for next-auth in npm
Critical
26 days ago
Auth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error)
npm
next-auth
High
26 days ago
Auth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers
npm
next-auth, @auth/core
Critical
26 days ago
Auth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass
npm
next-auth, @auth/core
Moderate
26 days ago
Auth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them
npm
next-auth, @auth/core
High
over 3 years ago
Missing proper state, nonce and PKCE checks for OAuth authentication
npm
next-auth
Potential
Moderate
almost 4 years ago
Upstash Adapter missing token verification
npm
@next-auth/upstash-redis-adapter
Low
about 4 years ago
next-auth before v4.10.2 and v3.29.9 leaks excessive information into log
npm
next-auth
Critical
about 4 years ago
NextAuth.js before 4.10.3 and 3.29.10 sending verification requests (magic link) to unwanted emails
npm
next-auth
Moderate
about 4 years ago
URL Redirection to Untrusted Site ('Open Redirect') in next-auth
npm
next-auth
Moderate
over 4 years ago
NextAuth.js default redirect callback vulnerable to open redirects
npm
next-auth