Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

next-auth — Vulnerabilities & Security Advisories 14

All 14 CVE vulnerabilities found in next-auth, with AI-generated Chinese analysis, references, and POCs.

The next-auth vulnerability aggregation page serves as a centralized resource for tracking security weaknesses associated with the popular authentication library for JavaScript and TypeScript applications. This section compiles a comprehensive list of reported vulnerabilities, covering the historical period from the library's initial public release through the most recent security advisories issued by the maintainers. By organizing this data into a single, accessible interface, the page aims to provide clarity on the evolving threat landscape surrounding next-auth and its dependencies. Users can utilize this resource to track vendor advisories and monitor the status of open or patched issues as they are disclosed. It also allows developers to understand specific weakness classes affecting the application, such as session fixation or improper authorization checks, and how they interact with common frameworks like Next.js. Furthermore, the page offers a detailed look at a product's vulnerability history, enabling security teams and individual contributors to assess risk exposure over time. This context is essential for making informed decisions about upgrading to secure versions or implementing temporary mitigations in production environments. The information presented here supports proactive security hygiene by highlighting known issues and their resolution statuses without requiring manual searching across multiple documentation sources or commit logs. Ultimately, this aggregation provides a transparent view of the library's security posture, helping the community maintain safe and reliable authentication implementations.

Vendor: nextauthjs

CVE IDTitleCVSSSeverityPublished
CVE-2026-73421 NextAuth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error) CWE-285 9.1 Critical2026-08-13
CVE-2026-73420 NextAuth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass CWE-180 9.1 Critical2026-08-13
CVE-2026-73419 NextAuth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them CWE-345 6.8 Medium2026-08-12
CVE-2026-73418 NextAuth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers CWE-20 7.5 High2026-08-12
CVE-2023-48309 next-auth vulnerable to possible user mocking that bypasses basic authentication CWE-285 5.3 Medium2023-11-20
CVE-2023-27490 Missing proper state, nonce and PKCE checks for OAuth authentication in next-auth CWE-384 8.1 High2023-03-09
CVE-2022-39263 NextAuth.js Upstash Adapter missing token verification CWE-287 6.8 Medium2022-09-28
CVE-2022-35924 Verification requests (magic link) sent to unwanted emails CWE-20 9.1 Critical2022-08-02
CVE-2022-31186 Leakage of excessive information into log in next-auth CWE-532 3.3 Low2022-08-01
CVE-2022-31127 Improper handling of email input in next-auth CWE-79 7.1 High2022-07-06
CVE-2022-31093 Improper Handling of `callbackUrl` parameter in next-auth CWE-754 7.5 High2022-06-27
CVE-2022-29214 URL Redirection to Untrusted Site ('Open Redirect') in next-auth CWE-601 6.1 Medium2022-05-20
CVE-2022-24858 Default redirect callback vulnerable to open redirects CWE-290 6.1 Medium2022-04-19
CVE-2021-21310 Token verification bug in next-auth CWE-290 6.1 Medium2021-02-11

All 14 known CVE vulnerabilities affecting next-auth with full Chinese analysis, references, and POCs where available.