14 Total advisories
14 Vulnerabilities
0 Malware
Vulnerabilities
MEDIUM 6.8
GHSA-x445-f3h2-j279
Auth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them
HIGH 7.5
GHSA-xmf8-cvqr-rfgj
Auth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers
UNKNOWN
GHSA-7rqj-j65f-68wh
Auth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass
UNKNOWN
GHSA-8fpg-xm3f-6cx3
Auth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error)
UNKNOWN
CVE-2021-21310
Token verification bug in next-auth
UNKNOWN
GHSA-5jpx-9hw9-2fx4
NextAuthjs Email misdelivery Vulnerability
MEDIUM 5.3
CVE-2023-48309
Possible user mocking that bypasses basic authentication
HIGH 8.1
CVE-2023-27490
Missing proper state, nonce and PKCE checks for OAuth authentication
CRITICAL 9.1
CVE-2022-35924
NextAuth.js before 4.10.3 and 3.29.10 sending verification requests (magic link) to unwanted emails
LOW 3.3
CVE-2022-31186
next-auth before v4.10.2 and v3.29.9 leaks excessive information into log
HIGH 7.1
CVE-2022-31127
Improper handling of email input
HIGH 7.5
CVE-2022-31093
Improper Handling of `callbackUrl` parameter in next-auth
MEDIUM 6.1
CVE-2022-29214
URL Redirection to Untrusted Site ('Open Redirect') in next-auth
MEDIUM 6.1
CVE-2022-24858
NextAuth.js default redirect callback vulnerable to open redirects
Ready to move
Start Securing
Free, no credit card | First findings in minutes