3 Total advisories
3 Vulnerabilities
0 Malware
Vulnerabilities
MEDIUM 6.8
GHSA-x445-f3h2-j279
Auth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them
HIGH 7.5
GHSA-xmf8-cvqr-rfgj
Auth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers
UNKNOWN
GHSA-7rqj-j65f-68wh
Auth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass
Ready to move
Start Securing
Free, no credit card | First findings in minutes