Skip to main content

Vendor archive

auth0 CVEs

Beta · best-effort

41 CVEs tagged to vendor auth04 Critical, 19 High, 18 Medium, 0 Low, 0 Unrated.

CVE-2026-42280

Published May 27, 2026

Auth0.js is a client-side JavaScript library for Auth0. From 8.11.0 to 9.32.0, under specific preconditions, the Auth0.js SDK may improperly return user profile information using…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-40155

Published Apr 17, 2026

The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. In versions 4.12.0 through 4.17.1, simultaneous requests that trigger a nonce retr…

CVSS 5.4 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-34236

Published Apr 1, 2026

Auth0-PHP is a PHP SDK for Auth0 Authentication and Management APIs. From version 8.0.0 to before version 8.19.0, in applications built with the Auth0 PHP SDK, cookies are encrypt…

CVSS 8.2 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-67716

Published Dec 11, 2025

The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. Versions 4.9.0 through 4.12.1 contain an input-validation flaw in the returnTo par…

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-67490

Published Dec 10, 2025

The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. When using versions 4.11.0 through 4.11.2 and 4.12.0, simultaneous requests on the…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-65945

Published Dec 4, 2025

auth0/node-jws is a JSON Web Signature implementation for Node.js. In versions 3.2.2 and earlier and version 4.0.0, auth0/node-jws has an improper signature verification vulnerabi…

CVSS 7.5 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2022-23539

Published Dec 23, 2022

Versions `<=8.5.1` of `jsonwebtoken` library could be misconfigured so that legacy, insecure key types are used for signature verification. For example, DSA keys could be used wit…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-23540

Published Dec 22, 2022

In versions `<=8.5.1` of `jsonwebtoken` library, lack of algorithm definition in the `jwt.verify()` function can lead to signature validation bypass due to defaulting to the `none…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-23541

Published Dec 22, 2022

jsonwebtoken is an implementation of JSON Web Tokens. Versions `<= 8.5.1` of `jsonwebtoken` library can be misconfigured so that passing a poorly implemented key retrieval functio…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-23505

Published Dec 13, 2022

Passport-wsfed-saml2 is a ws-federation protocol and SAML2 tokens authentication provider for Passport. In versions prior to 4.6.3, a remote attacker may be able to bypass WSFed a…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-29172

Published May 5, 2022

Auth0 is an authentication broker that supports both social and enterprise identity providers, including Active Directory, LDAP, Google Apps, and Salesforce. In versions before `1…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-24794

Published Mar 31, 2022

Express OpenID Connect is an Express JS middleware implementing sign on for Express web apps using OpenID Connect. Users of the `requiresAuth` middleware, either directly or throu…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-43812

Published Dec 16, 2021

The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. Versions before 1.6.2 do not filter out certain returnTo parameter values from the…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-41246

Published Dec 9, 2021

Express OpenID Connect is express JS middleware implementing sign on for Express web apps using OpenID Connect. Versions before and including `2.5.1` do not regenerate the session…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-32702

Published Jun 25, 2021

The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. Versions before and including `1.4.1` are vulnerable to reflected XSS. An attacker…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2021-32641

Published Jun 4, 2021

auth0-lock is Auth0's signin solution. Versions of nauth0-lock before and including `11.30.0` are vulnerable to reflected XSS. An attacker can execute arbitrary code when the libr…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2020-15259

Published Nov 6, 2020

ad-ldap-connector's admin panel before version 5.0.13 does not provide csrf protection, which when exploited may result in remote code execution or confidential data loss. CSRF ex…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2020-15240

Published Oct 21, 2020

omniauth-auth0 (rubygems) versions >= 2.3.0 and < 2.4.1 improperly validate the JWT token signature when using the `jwt_validator.verify` method. Improper validation of the JWT to…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2020-15119

Published Aug 20, 2020

In auth0-lock versions before and including 11.25.1, dangerouslySetInnerHTML is used to update the DOM. When dangerouslySetInnerHTML is used, the application and its users might b…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-15125

Published Jul 29, 2020

In auth0 (npm package) versions before 2.27.1, a DenyList of specific keys that should be sanitized from the request object contained in the error object is used. The key for Auth…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2020-15084

Published Jun 30, 2020

In express-jwt (NPM package) up and including version 5.3.3, the algorithms entry to be specified in the configuration is not being enforced. When algorithms is not specified in t…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2020-5263

Published Apr 9, 2020

auth0.js (NPM package auth0-js) greater than version 8.0.0 and before version 9.12.3 has a vulnerability. In the case of an (authentication) error, the error object returned by th…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-7948

Published Apr 1, 2020

An issue was discovered in the Login by Auth0 plugin before 4.0.0 for WordPress. A user can perform an insecure direct object reference.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-7947

Published Apr 1, 2020

An issue was discovered in the Login by Auth0 plugin before 4.0.0 for WordPress. It has numerous fields that can contain data that is pulled from different sources. One issue with…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-25 of 41 CVEsPage 1 of 2