NextAuthjs Email misdelivery Vulnerability
Modified: 9/10/2026
package
pkg:npm/next-auth
NextAuthjs Email misdelivery Vulnerability
Modified: 9/10/2026
Missing proper state, nonce and PKCE checks for OAuth authentication
Modified: 9/10/2026
Auth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass
Modified: 9/10/2026
Auth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error)
Modified: 8/12/2026
NextAuth.js default redirect callback vulnerable to open redirects
Modified: 11/8/2023
Improper Handling of `callbackUrl` parameter in next-auth
Modified: 11/8/2023
next-auth before v4.10.2 and v3.29.9 leaks excessive information into log
Modified: 11/8/2023
Token verification bug in next-auth
Modified: 7/8/2026
Improper handling of email input
Modified: 11/8/2023
URL Redirection to Untrusted Site ('Open Redirect') in next-auth
Modified: 11/8/2023
Possible user mocking that bypasses basic authentication
Modified: 9/10/2026
Auth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them
Modified: 9/10/2026
Auth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers
Modified: 9/10/2026
NextAuth.js before 4.10.3 and 3.29.10 sending verification requests (magic link) to unwanted emails
Modified: 11/8/2023