@auth/core
npm3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting @auth/corepage 1 of 1
- CVE-2026-73418HIGHCVSS 7.5EG 7.5✓ Fixed in 0.41.32026-08-12
NextAuth.js provides authentication for Next.js. Prior to @auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, the exported getToken() helper in the next-auth/jwt and @auth/core/jwt modules can throw an uncaught exception when it rea…
- CVE-2026-73419MEDIUMCVSS 6.8EG 6.8✓ Fixed in 0.41.32026-08-12
NextAuth.js provides authentication for Next.js. Prior to@auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, Auth.js stores the OAuth/OIDC anti-CSRF checks state, nonce, and the PKCE verifier in global cookies that are not bound to …
- CVE-2026-73420CRITICALCVSS 9.1EG 9.1✓ Fixed in 0.41.32026-07-23
NextAuth.js provides authentication for Next.js. Prior to @auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, the defaultNormalizer used by the email and magic-link sign-in flow validates an address before applying Unicode normaliza…
Check whether @auth/core is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for @auth/core CVEs against the assets you own.
Start Free Scan →