14 Total advisories
14 Vulnerabilities
0 Malware
Dependency scanning
Check whether next-auth is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
HIGH 7.5
CVE-2026-73418
Auth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers
MEDIUM 6.8
CVE-2026-73419
Auth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them
UNKNOWN
CVE-2026-73420
Auth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass
UNKNOWN
GHSA-5jpx-9hw9-2fx4
NextAuthjs Email misdelivery Vulnerability
MEDIUM 5.3
CVE-2023-48309
Possible user mocking that bypasses basic authentication
HIGH 8.1
CVE-2023-27490
Missing proper state, nonce and PKCE checks for OAuth authentication
UNKNOWN
CVE-2026-73421
Auth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error)
UNKNOWN
CVE-2021-21310
Token verification bug in next-auth
CRITICAL 9.1
CVE-2022-35924
NextAuth.js before 4.10.3 and 3.29.10 sending verification requests (magic link) to unwanted emails
LOW 3.3
CVE-2022-31186
next-auth before v4.10.2 and v3.29.9 leaks excessive information into log
HIGH 7.1
CVE-2022-31127
Improper handling of email input
HIGH 7.5
CVE-2022-31093
Improper Handling of `callbackUrl` parameter in next-auth
MEDIUM 6.1
CVE-2022-29214
URL Redirection to Untrusted Site ('Open Redirect') in next-auth
MEDIUM 6.1
CVE-2022-24858
NextAuth.js default redirect callback vulnerable to open redirects
Browse more npm advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes