« Volver al listado

Nextauth.js

Nextauth.js Next-auth: vulnerabilidades y CVE

Nextauth.js Next-auth tiene 13 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE13
Últimos 12 meses4
Críticas3
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-73421Crítica (9.1)0.64%—13 ago 2026
NextAuth.js provides authentication for Next.js. From next-auth 5.0.0-beta.0 until 5.0.0-beta.32, applications that gate access by checking only for the existence of the auth object returned by the auth() wrapper can…
CVE-2026-73420Crítica (9.1)0.73%—13 ago 2026
NextAuth.js provides authentication for Next.js. Prior to @auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, the defaultNormalizer used by the email and magic-link sign-in flow validates an address before…
CVE-2026-73419Media (6.8)0.25%—12 ago 2026
NextAuth.js provides authentication for Next.js. Prior to@auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, Auth.js stores the OAuth/OIDC anti-CSRF checks state, nonce, and the PKCE verifier in global cookies…
CVE-2026-73418Alta (7.5)0.88%—12 ago 2026
NextAuth.js provides authentication for Next.js. Prior to @auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, the exported getToken() helper in the next-auth/jwt and @auth/core/jwt modules can throw an uncaught…
CVE-2023-48309Media (5.3)0.70%—20 nov 2023
NextAuth.js provides authentication for Next.js. `next-auth` applications prior to version 4.24.5 that rely on the default Middleware authorization are affected by a vulnerability. A bad actor could create an empty/mock…
CVE-2023-27490Alta (8.8)0.54%—9 mar 2023
NextAuth.js is an open source authentication solution for Next.js applications. `next-auth` applications using OAuth provider versions before `v4.20.1` have been found to be subject to an authentication vulnerability. A…
CVE-2022-39263Alta (8.1)0.70%—28 sept 2022
`@next-auth/upstash-redis-adapter` is the Upstash Redis adapter for NextAuth.js, which provides authentication for Next.js. Applications that use `next-auth` Email Provider and `@next-auth/upstash-redis-adapter` before…
CVE-2022-35924Crítica (9.1)1.4%—2 ago 2022
NextAuth.js is a complete open source authentication solution for Next.js applications. `next-auth` users who are using the `EmailProvider` either in versions before `4.10.3` or `3.29.10` are affected. If an attacker…
CVE-2022-31127Media (6.1)1.1%—6 jul 2022
NextAuth.js is a complete open source authentication solution for Next.js applications. An attacker can pass a compromised input to the e-mail [signin…
CVE-2022-31093Alta (7.5)1.7%—27 jun 2022
NextAuth.js is a complete open source authentication solution for Next.js applications. In affected versions an attacker can send a request to an app using NextAuth.js with an invalid `callbackUrl` query parameter,…
CVE-2022-29214Media (6.1)0.66%—21 may 2022
NextAuth.js (next-auth) is am open source authentication solution for Next.js applications. Prior to versions 3.29.3 and 4.3.3, an open redirect vulnerability is present when the developer is implementing an OAuth 1…
CVE-2022-24858Media (6.1)0.79%—19 abr 2022
next-auth v3 users before version 3.29.2 are impacted. next-auth version 4 users before version 4.3.2 are also impacted. Upgrading to 3.29.2 or 4.3.2 will patch this vulnerability. If you are not able to upgrade for any…
CVE-2021-21310Media (5.9)1.7%—11 feb 2021
NextAuth.js (next-auth) is am open source authentication solution for Next.js applications. In next-auth before version 3.3.0 there is a token verification vulnerability. Implementations using the Prisma database…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application3
  2. T1078.001 Default Accounts2
  3. T1499.004 Application or System Exploitation1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.