Next.js-based authentication library that serves as a widely embedded session and credential-handling middleware across Next.js applications. Vulnerabilities affecting this vendor skew toward serious outcomes, with a meaningful share reaching critical severity, and cluster around authentication and authorization mechanisms including authentication bypass through spoofing, improper access control, open-redirect chains, cross-site request forgery, and session-management weaknesses. Defenders should treat this vendor's disclosures as high-priority within the Next.js ecosystem and inventory downstream applications that integrate this library, since remediation typically depends on application-level updates; current severity and exploitation details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nextauth.Js over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-35924CRITICAL NextAuth.js is a complete open source authentication solution for Next.js applications. `next-auth` users who are using the `EmailProvider` either in versions before `4.10.3` or `3 | Aug 2, 2022 | 9.1 | 29 | NO | NO |
CVE-2023-27490HIGH NextAuth.js is an open source authentication solution for Next.js applications. `next-auth` applications using OAuth provider versions before `v4.20.1` have been found to be subjec | Mar 9, 2023 | 8.8 | 26 | NO | NO |
CVE-2022-39263HIGH `@next-auth/upstash-redis-adapter` is the Upstash Redis adapter for NextAuth.js, which provides authentication for Next.js. Applications that use `next-auth` Email Provider and `@n | Sep 28, 2022 | 8.1 | 26 | NO | NO |
CVE-2022-31093HIGH NextAuth.js is a complete open source authentication solution for Next.js applications. In affected versions an attacker can send a request to an app using NextAuth.js with an inva | Jun 27, 2022 | 7.5 | 25 | NO | NO |
CVE-2022-29214MEDIUM NextAuth.js (next-auth) is am open source authentication solution for Next.js applications. Prior to versions 3.29.3 and 4.3.3, an open redirect vulnerability is present when the d | May 21, 2022 | 6.1 | 22 | NO | NO |
CVE-2022-24858MEDIUM next-auth v3 users before version 3.29.2 are impacted. next-auth version 4 users before version 4.3.2 are also impacted. Upgrading to 3.29.2 or 4.3.2 will patch this vulnerability. | Apr 19, 2022 | 6.1 | 22 | NO | NO |
CVE-2022-31127MEDIUM NextAuth.js is a complete open source authentication solution for Next.js applications. An attacker can pass a compromised input to the e-mail [signin endpoint](https://next-auth.j | Jul 6, 2022 | 6.1 | 21 | NO | NO |
CVE-2021-21310MEDIUM NextAuth.js (next-auth) is am open source authentication solution for Next.js applications. In next-auth before version 3.3.0 there is a token verification vulnerability. Implement | Feb 11, 2021 | 5.9 | 20 | NO | NO |
CVE-2023-48309MEDIUM NextAuth.js provides authentication for Next.js. `next-auth` applications prior to version 4.24.5 that rely on the default Middleware authorization are affected by a vulnerability. | Nov 20, 2023 | 5.3 | 19 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nextauth.Js.
Media articles that mention a CVE ID that affects a product developed by Nextauth.Js — matched by CVE ID, not by vendor name.