14 Total advisories
14 Vulnerabilities
0 Malware

Dependency scanning

Check whether next-auth is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

HIGH 7.5
npm

CVE-2026-73418

Auth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers

MEDIUM 6.8
npm

CVE-2026-73419

Auth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them

UNKNOWN
npm

CVE-2026-73420

Auth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass

UNKNOWN
npm

GHSA-5jpx-9hw9-2fx4

NextAuthjs Email misdelivery Vulnerability

MEDIUM 5.3
npm

CVE-2023-48309

Possible user mocking that bypasses basic authentication

HIGH 8.1
npm

CVE-2023-27490

Missing proper state, nonce and PKCE checks for OAuth authentication

UNKNOWN
npm

CVE-2026-73421

Auth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error)

UNKNOWN
npm

CVE-2021-21310

Token verification bug in next-auth

CRITICAL 9.1
npm

CVE-2022-35924

NextAuth.js before 4.10.3 and 3.29.10 sending verification requests (magic link) to unwanted emails

LOW 3.3
npm

CVE-2022-31186

next-auth before v4.10.2 and v3.29.9 leaks excessive information into log

HIGH 7.1
npm

CVE-2022-31127

Improper handling of email input

HIGH 7.5
npm

CVE-2022-31093

Improper Handling of `callbackUrl` parameter in next-auth

MEDIUM 6.1
npm

CVE-2022-29214

URL Redirection to Untrusted Site ('Open Redirect') in next-auth

MEDIUM 6.1
npm

CVE-2022-24858

NextAuth.js default redirect callback vulnerable to open redirects

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes