VendorsNextAuth.jsnext-authall versions
Vulnerabilities

NextAuth.js next-auth

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2022-35924
Verification requests (magic link) sent to unwanted emails
Published 2022-08-02 · Modified
9.1EPSS 0.014
CVE-2023-27490
Missing proper state, nonce and PKCE checks for OAuth authentication in next-auth
Published 2023-03-09 · Modified
8.8EPSS 0.005
CVE-2022-39263
NextAuth.js Upstash Adapter missing token verification
Published 2022-09-28 · Modified
8.1EPSS 0.006
CVE-2022-31093
Improper Handling of `callbackUrl` parameter in next-auth
Published 2022-06-27 · Modified
7.5EPSS 0.017
CVE-2022-31127
Improper handling of email input in next-auth
Published 2022-07-06 · Modified
7.1EPSS 0.011
CVE-2021-21310
Token verification bug in next-auth
Published 2021-02-11 · Modified
6.1EPSS 0.017
CVE-2022-24858
Default redirect callback vulnerable to open redirects
Published 2022-04-19 · Modified
6.1EPSS 0.008
CVE-2022-29214
URL Redirection to Untrusted Site ('Open Redirect') in next-auth
Published 2022-05-20 · Modified
6.1EPSS 0.007
CVE-2023-48309
next-auth vulnerable to possible user mocking that bypasses basic authentication
Published 2023-11-20 · Modified
5.3EPSS 0.007