react-native-auth0 SDK 的 Web 平台实现在服务器端渲染(SSR)环境中,未将其内存中的令牌缓存隔离到独立的用户会话。在这种模块状态会在 HTTP 请求之间保持存在的运行时环境下,根据所列前提条件,缓存在模块内存中的令牌可能会在由同一服务器运行时处理的后续请求中被检索到。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Auth0 | react-native-auth0 | 5.0.0 ~ 5.11.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-85982 | 9.0 CRITICAL | Stored Cross-Site Scripting (XSS) in Auth0 AD/LDAP Connector |
| CVE-2026-85983 | 7.8 HIGH | Local Privilege Escalation in Auth0 AD/LDAP Connector |
| CVE-2026-85981 | 6.7 MEDIUM | Unauthenticated Localhost Admin Panel in Auth0 AD/LDAP Connector |
No comments yet