Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

auth0 — Vulnerabilities & Security Advisories 36

Browse all 36 CVE security advisories affecting auth0. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Auth0 operates as a cloud-based identity and access management platform, primarily serving developers who require secure authentication and authorization services for web and mobile applications. Its architecture handles sensitive user credentials and session tokens, making it a critical component in modern software ecosystems. Historically, vulnerabilities within its ecosystem have frequently involved cross-site scripting (XSS), broken access control, and security misconfigurations that could lead to privilege escalation or unauthorized data access. With thirty recorded Common Vulnerabilities and Exposures (CVEs), the platform has faced scrutiny regarding its implementation of security controls. While no single catastrophic breach has publicly defined its history, the cumulative nature of these flaws highlights the inherent risks in complex third-party identity providers. Organizations relying on this service must rigorously monitor updates and enforce strict configuration standards to mitigate potential exploitation vectors inherent in its extensive feature set.

CVE ID Title CVSS Severity Published
CVE-2026-50157 Auth0 Symfony: Bearer Token Accepted via URL Query Parameter in Auth0 Symfony SDK — symfony CWE-598 6.5 Medium 2026-09-14
CVE-2026-84685 Improper Cache Isolation in auth0/react-native-auth0 SDK Web Platform Credential Management — react-native-auth0 CWE-488 6.5 Medium 2026-09-08
CVE-2026-85983 Local Privilege Escalation in Auth0 AD/LDAP Connector — Auth0 AD/LDAP Connector CWE-94 7.8 High 2026-09-08
CVE-2026-85982 Stored Cross-Site Scripting (XSS) in Auth0 AD/LDAP Connector — Auth0 AD/LDAP Connector CWE-79 9.0 Critical 2026-09-08
CVE-2026-85981 Unauthenticated Localhost Admin Panel in Auth0 AD/LDAP Connector — Auth0 AD/LDAP Connector CWE-306 6.7 Medium 2026-09-08
CVE-2026-42280 Improper Permission Checking in Auth.js SDK — auth0.js CWE-863 7.1 High 2026-05-27
CVE-2026-40155 Auth0 Next.js SDK has Improper Proxy Cache Lookup — nextjs-auth0 CWE-863 5.4 Medium 2026-04-17
CVE-2026-34236 Auth0 PHP SDK Insufficient Entropy in Cookie Encryption — auth0-PHP CWE-331 8.2 High 2026-04-01
CVE-2025-68129 Auth0-PHP SDK has Improper Audience Validation — auth0-PHP CWE-863 6.8 Medium 2025-12-17
CVE-2025-67716 Auth0 Next.js SDK has Improper Validation of Query Parameters — nextjs-auth0 CWE-184 5.7 Medium 2025-12-11
CVE-2025-67490 Auth0 Next.js SDK has Improper Request Caching Lookup — nextjs-auth0 CWE-863 5.4 Medium 2025-12-10
CVE-2025-65945 auth0/node-jws improper HMAC signature verification vulnerability — node-jws CWE-347 7.5 High 2025-12-04
CVE-2025-58769 auth0-PHP: Improper File Type Handling in Bulk User Import — laravel-auth0 CWE-22 3.3 Low 2025-10-01
CVE-2025-48947 NextJS-Auth0 SDK Vulnerable to CDN Caching of Session Cookies — nextjs-auth0 CWE-525 6.5AI Medium AI 2025-06-04
CVE-2025-48951 Auth0-PHP SDK Deserialization of Untrusted Data vulnerability — auth0-PHP CWE-502 9.1AI Critical AI 2025-06-03
CVE-2025-47275 Brute Force Authentication Tags of CookieStore Sessions in Auth0-PHP SDK — auth0-PHP CWE-287 9.1 Critical 2025-05-15
CVE-2025-46573 passport-wsfed-saml2 Has SAML Authentication Bypass via Attribute Smuggling — passport-wsfed-saml2 CWE-287 7.4AI High AI 2025-05-06
CVE-2025-46572 passport-wsfed-saml2 Has SAML Authentication Bypass via Signature Wrapping — passport-wsfed-saml2 CWE-287 7.4AI High AI 2025-05-06
CVE-2025-46344 Auth0 NextJS SDK v4 Missing Session Invalidation — nextjs-auth0 CWE-613 9.1AI Critical AI 2025-04-29
CVE-2023-6813 Login by Auth0 <= 4.6.0 - Reflected Cross-Site Scripting via wle — Login by Auth0 CWE-79 6.1 Medium 2024-07-10
CVE-2022-23539 jsonwebtoken unrestricted key type could lead to legacy keys usage — node-jsonwebtoken CWE-327 5.9 Medium 2022-12-22
CVE-2022-23540 jsonwebtoken vulnerable to signature validation bypass due to insecure default algorithm in jwt.verify() — node-jsonwebtoken CWE-287 6.4 Medium 2022-12-22
CVE-2022-23541 jsonwebtoken's insecure implementation of key retrieval function could lead to Forgeable Public/Private Tokens from RSA to HMAC — node-jsonwebtoken CWE-287 5.0 Medium 2022-12-22
CVE-2022-23505 Passport-wsfed-saml2 vulnerable to Authentication Bypass for WSFed authentication — passport-wsfed-saml2 CWE-287 5.3 Medium 2022-12-13
CVE-2022-29172 HTML injection with additional signup fields — lock CWE-79 6.1 Medium 2022-05-05
CVE-2022-24794 Open Redirect in express-openid-connect — express-openid-connect CWE-601 7.5 High 2022-03-31
CVE-2021-43812 Open redirect in nextjs-auth0 — nextjs-auth0 CWE-601 6.4 Medium 2021-12-16
CVE-2021-41246 Session fixation in express-openid-connect — express-openid-connect CWE-384 4.6 Medium 2021-12-09
CVE-2021-32702 Reflected XSS from the callback handler's error query parameter — nextjs-auth0 CWE-79 8.0 High 2021-06-25
CVE-2021-32641 Reflected XSS when using flashMessages — lock CWE-79 8.1 High 2021-06-04

This page lists every published CVE security advisory associated with auth0. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.