Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

next-auth — Vulnerabilities & Security Advisories 14

All 14 CVE vulnerabilities found in next-auth, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerability records for the open-source authentication library next-auth, focusing on implementation flaws within the identity and access control component. The collection encompasses reported defects ranging from broken object equality checks to potential remote code execution vectors, covering advisories published from 2021 through 2024. Readers can use this resource to track the project's security posture over time, understand common weakness classes affecting authentication flows, and review the complete vulnerability history associated with the product. The data is organized to facilitate trend analysis and comparative study of how specific bug patterns evolve across different releases.

Vendor: nextauthjs

CVE ID Title CVSS Severity Published
CVE-2026-73421 NextAuth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error) CWE-285 9.1 Critical 2026-08-13
CVE-2026-73420 NextAuth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass CWE-180 9.1 Critical 2026-08-13
CVE-2026-73419 NextAuth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them CWE-345 6.8 Medium 2026-08-12
CVE-2026-73418 NextAuth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers CWE-20 7.5 High 2026-08-12
CVE-2023-48309 next-auth vulnerable to possible user mocking that bypasses basic authentication CWE-285 5.3 Medium 2023-11-20
CVE-2023-27490 Missing proper state, nonce and PKCE checks for OAuth authentication in next-auth CWE-384 8.1 High 2023-03-09
CVE-2022-39263 NextAuth.js Upstash Adapter missing token verification CWE-287 6.8 Medium 2022-09-28
CVE-2022-35924 Verification requests (magic link) sent to unwanted emails CWE-20 9.1 Critical 2022-08-02
CVE-2022-31186 Leakage of excessive information into log in next-auth CWE-532 3.3 Low 2022-08-01
CVE-2022-31127 Improper handling of email input in next-auth CWE-79 7.1 High 2022-07-06
CVE-2022-31093 Improper Handling of `callbackUrl` parameter in next-auth CWE-754 7.5 High 2022-06-27
CVE-2022-29214 URL Redirection to Untrusted Site ('Open Redirect') in next-auth CWE-601 6.1 Medium 2022-05-20
CVE-2022-24858 Default redirect callback vulnerable to open redirects CWE-290 6.1 Medium 2022-04-19
CVE-2021-21310 Token verification bug in next-auth CWE-290 6.1 Medium 2021-02-11

All 14 known CVE vulnerabilities affecting next-auth with full Chinese analysis, references, and POCs where available.