Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2570▼ 300 respecto a la semana anterior
Críticas / altas1348▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
14 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Crítica (9.1) | 0.64% | — | Nextauth.js Next-authAI | 13/8/2026 | 18/9/2026 | NextAuth.js provides authentication for Next.js. From next-auth 5.0.0-beta.0 until 5.0.0-beta.32, applications that gate access by checking only for the existence of the auth object returned by the auth() wrapper can fail open when Auth.js has a server configuration error. In middleware, Route Handlers, React Server… | |
| Pendiente de análisis | Crítica (9.1) | 0.73% | — | Nextauth.js Next-authAICoreAI | 13/8/2026 | 18/9/2026 | NextAuth.js provides authentication for Next.js. Prior to @auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, the defaultNormalizer used by the email and magic-link sign-in flow validates an address before applying Unicode normalization. An address can contain a Unicode character such as U+FF20 FULLWIDTH… | |
| Pendiente de análisis | Media (6.8) | 0.25% | — | Nextauth.js Next-authAICoreAI | 12/8/2026 | 9/9/2026 | NextAuth.js provides authentication for Next.js. Prior to@auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, Auth.js stores the OAuth/OIDC anti-CSRF checks state, nonce, and the PKCE verifier in global cookies that are not bound to the provider that created them. On callback, a check value minted during a… | |
| Pendiente de análisis | Alta (7.5) | 0.88% | — | Nextauth @auth/coreAINextauth.js Next-authAI | 12/8/2026 | 9/9/2026 | NextAuth.js provides authentication for Next.js. Prior to @auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, the exported getToken() helper in the next-auth/jwt and @auth/core/jwt modules can throw an uncaught exception when it reads a malformed Authorization: Bearer header. When no session cookie is present,… | |
| Modificada | Media (5.3) | 0.70% | — | Nextauth.js Next-auth | 20/11/2023 | 17/6/2026 | NextAuth.js provides authentication for Next.js. `next-auth` applications prior to version 4.24.5 that rely on the default Middleware authorization are affected by a vulnerability. A bad actor could create an empty/mock user, by getting hold of a NextAuth.js-issued JWT from an interrupted OAuth sign-in flow (state,… | |
| Modificada | Alta (8.8) | 0.54% | — | Nextauth.js Next-auth | 9/3/2023 | 17/6/2026 | NextAuth.js is an open source authentication solution for Next.js applications. `next-auth` applications using OAuth provider versions before `v4.20.1` have been found to be subject to an authentication vulnerability. A bad actor who can read traffic on the victim's network or who is able to social engineer the victim… | |
| Modificada | Alta (8.1) | 0.70% | — | Nextauth.js Next-auth | 28/9/2022 | 17/6/2026 | `@next-auth/upstash-redis-adapter` is the Upstash Redis adapter for NextAuth.js, which provides authentication for Next.js. Applications that use `next-auth` Email Provider and `@next-auth/upstash-redis-adapter` before v3.0.2 are affected by this vulnerability. The Upstash Redis adapter implementation did not check… | |
| Modificada | Crítica (9.1) | 1.4% | — | Nextauth.js Next-auth | 2/8/2022 | 17/6/2026 | NextAuth.js is a complete open source authentication solution for Next.js applications. `next-auth` users who are using the `EmailProvider` either in versions before `4.10.3` or `3.29.10` are affected. If an attacker could forge a request that sent a comma-separated list of emails (eg.:… | |
| Modificada | Baja (3.3) | 0.26% | — | Next-auth Nextauth.js | 1/8/2022 | 17/6/2026 | NextAuth.js is a complete open source authentication solution for Next.js applications. An information disclosure vulnerability in `next-auth` before `v4.10.2` and `v3.29.9` allows an attacker with log access privilege to obtain excessive information such as an identity provider's secret in the log (which is thrown… | |
| Modificada | Media (6.1) | 1.1% | — | Nextauth.js Next-auth | 6/7/2022 | 17/6/2026 | NextAuth.js is a complete open source authentication solution for Next.js applications. An attacker can pass a compromised input to the e-mail [signin endpoint](https://next-auth.js.org/getting-started/rest-api#post-apiauthsigninprovider) that contains some malicious HTML, tricking the e-mail server to send it to the… | |
| Modificada | Alta (7.5) | 1.7% | — | Nextauth.js Next-auth | 27/6/2022 | 17/6/2026 | NextAuth.js is a complete open source authentication solution for Next.js applications. In affected versions an attacker can send a request to an app using NextAuth.js with an invalid `callbackUrl` query parameter, which internally is converted to a `URL` object. The URL instantiation would fail due to a malformed URL… | |
| Modificada | Media (6.1) | 0.66% | — | Nextauth.js Next-auth | 21/5/2022 | 17/6/2026 | NextAuth.js (next-auth) is am open source authentication solution for Next.js applications. Prior to versions 3.29.3 and 4.3.3, an open redirect vulnerability is present when the developer is implementing an OAuth 1 provider. Versions 3.29.3 and 4.3.3 contain a patch for this issue. The maintainers recommend adding a… | |
| Modificada | Media (6.1) | 0.79% | — | Nextauth.js Next-auth | 19/4/2022 | 17/6/2026 | next-auth v3 users before version 3.29.2 are impacted. next-auth version 4 users before version 4.3.2 are also impacted. Upgrading to 3.29.2 or 4.3.2 will patch this vulnerability. If you are not able to upgrade for any reason, you can add a configuration to your callbacks option. If you already have a `redirect`… | |
| Modificada | Media (5.9) | 1.7% | — | Nextauth.js Next-auth | 11/2/2021 | 17/6/2026 | NextAuth.js (next-auth) is am open source authentication solution for Next.js applications. In next-auth before version 3.3.0 there is a token verification vulnerability. Implementations using the Prisma database adapter in conjunction with the Email provider are impacted. Implementations using the Email provider with… |