Nextauth.js
Nextauth.js Next-auth: vulnerabilidades y CVE
Nextauth.js Next-auth tiene 13 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE13
Últimos 12 meses4
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-73421 | Crítica (9.1) | 0.64% | — | 13 ago 2026 | NextAuth.js provides authentication for Next.js. From next-auth 5.0.0-beta.0 until 5.0.0-beta.32, applications that gate access by checking only for the existence of the auth object returned by the auth() wrapper can… |
| CVE-2026-73420 | Crítica (9.1) | 0.73% | — | 13 ago 2026 | NextAuth.js provides authentication for Next.js. Prior to @auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, the defaultNormalizer used by the email and magic-link sign-in flow validates an address before… |
| CVE-2026-73419 | Media (6.8) | 0.25% | — | 12 ago 2026 | NextAuth.js provides authentication for Next.js. Prior to@auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, Auth.js stores the OAuth/OIDC anti-CSRF checks state, nonce, and the PKCE verifier in global cookies… |
| CVE-2026-73418 | Alta (7.5) | 0.88% | — | 12 ago 2026 | NextAuth.js provides authentication for Next.js. Prior to @auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, the exported getToken() helper in the next-auth/jwt and @auth/core/jwt modules can throw an uncaught… |
| CVE-2023-48309 | Media (5.3) | 0.70% | — | 20 nov 2023 | NextAuth.js provides authentication for Next.js. `next-auth` applications prior to version 4.24.5 that rely on the default Middleware authorization are affected by a vulnerability. A bad actor could create an empty/mock… |
| CVE-2023-27490 | Alta (8.8) | 0.54% | — | 9 mar 2023 | NextAuth.js is an open source authentication solution for Next.js applications. `next-auth` applications using OAuth provider versions before `v4.20.1` have been found to be subject to an authentication vulnerability. A… |
| CVE-2022-39263 | Alta (8.1) | 0.70% | — | 28 sept 2022 | `@next-auth/upstash-redis-adapter` is the Upstash Redis adapter for NextAuth.js, which provides authentication for Next.js. Applications that use `next-auth` Email Provider and `@next-auth/upstash-redis-adapter` before… |
| CVE-2022-35924 | Crítica (9.1) | 1.4% | — | 2 ago 2022 | NextAuth.js is a complete open source authentication solution for Next.js applications. `next-auth` users who are using the `EmailProvider` either in versions before `4.10.3` or `3.29.10` are affected. If an attacker… |
| CVE-2022-31127 | Media (6.1) | 1.1% | — | 6 jul 2022 | NextAuth.js is a complete open source authentication solution for Next.js applications. An attacker can pass a compromised input to the e-mail [signin… |
| CVE-2022-31093 | Alta (7.5) | 1.7% | — | 27 jun 2022 | NextAuth.js is a complete open source authentication solution for Next.js applications. In affected versions an attacker can send a request to an app using NextAuth.js with an invalid `callbackUrl` query parameter,… |
| CVE-2022-29214 | Media (6.1) | 0.66% | — | 21 may 2022 | NextAuth.js (next-auth) is am open source authentication solution for Next.js applications. Prior to versions 3.29.3 and 4.3.3, an open redirect vulnerability is present when the developer is implementing an OAuth 1… |
| CVE-2022-24858 | Media (6.1) | 0.79% | — | 19 abr 2022 | next-auth v3 users before version 3.29.2 are impacted. next-auth version 4 users before version 4.3.2 are also impacted. Upgrading to 3.29.2 or 4.3.2 will patch this vulnerability. If you are not able to upgrade for any… |
| CVE-2021-21310 | Media (5.9) | 1.7% | — | 11 feb 2021 | NextAuth.js (next-auth) is am open source authentication solution for Next.js applications. In next-auth before version 3.3.0 there is a token verification vulnerability. Implementations using the Prisma database… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.