CRITICALnpm
GHSA-7rqj-j65f-68wh· CVE-2026-73420Auth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass
Modified: 9/10/2026
package
pkg:npm/%40auth/core
Auth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass
Modified: 9/10/2026
Auth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them
Modified: 9/10/2026
Auth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers
Modified: 9/10/2026