3 Total advisories
3 Vulnerabilities
0 Malware
Dependency scanning
Check whether @auth/core is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
HIGH 7.5
CVE-2026-73418
Auth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers
MEDIUM 6.8
CVE-2026-73419
Auth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them
UNKNOWN
CVE-2026-73420
Auth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass
Browse more npm advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes