CVE-2025-67490

MEDIUM EPSS 6.8%
Published Dec 10, 20256mo ago · Modified Jun 17, 20262w ago
5.4 CVSS 3.1
Medium
Find Similar
Published Dec 10, 2025 6mo ago
Last Modified Jun 17, 2026 2w ago

Description

The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. When using versions 4.11.0 through 4.11.2 and 4.12.0, simultaneous requests on the same client may result in improper lookups in the TokenRequestCache for the request results. This issue is fixed in versions 4.11.2 and 4.12.1.

CVSS Details

Base Score
5.4
Exploitability
1.2
Impact
4.2
Vector string
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:N
Attack Vector Network
Attack Complexity High
Privileges Required Low
User Interaction Required
Scope Unchanged
Confidentiality High
Integrity Low
Availability None

Threat Intelligence

EPSS Exploit Probability
6.8% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-863 Incorrect Authorization Authorization

Affected Products 3

VendorProductVersionRange
auth0nextjs-auth04.11.0any
auth0nextjs-auth04.11.1any
auth0nextjs-auth04.12.0any

References 2

  • github.com https://github.com/auth0/nextjs-auth0/commit/26cc8a7c60f4b134700912736f991a25bd6bbf0b
    Patch
  • github.com https://github.com/auth0/nextjs-auth0/security/advisories/GHSA-wcgj-f865-c7j7
    Vendor Advisory

Remediation

  • github.com https://github.com/auth0/nextjs-auth0/commit/26cc8a7c60f4b134700912736f991a25bd6bbf0b
    Patch