5.4
CVE-2025-67490
- EPSS 0.21%
- Veröffentlicht 10.12.2025 22:16:08
- Zuletzt bearbeitet 25.09.2026 23:10:00
- Erkennungen
Auth0 Next.js SDK has Improper Request Caching Lookup
The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. When using versions 4.11.0 through 4.11.2 and 4.12.0, simultaneous requests on the same client may result in improper lookups in the TokenRequestCache for the request results. This issue is fixed in versions 4.11.2 and 4.12.1.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Auth0 ≫ Nextjs-auth0 Version 4.11.0 SwPlatform node.js
Auth0 ≫ Nextjs-auth0 Version 4.11.1 SwPlatform node.js
Auth0 ≫ Nextjs-auth0 Version 4.12.0 SwPlatform node.js
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.21% | 0.106 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 5.4 | 1.2 | 4.2 |
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:N
|
CWE-863 Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
https://github.com/auth0/nextjs-auth0/commit/26cc8a7c60f4b134700912736f991a25bd6bbf0b
https://github.com/auth0/nextjs-auth0/security/advisories/GHSA-wcgj-f865-c7j7