PT-2025-50552 · Auth0 · Auth0 Next.Js Sdk

Published

2025-12-10

·

Updated

2025-12-11

·

CVE-2025-67490

CVSS v3.1

5.4

Medium

VectorAV:N/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Auth0 Next.js SDK versions 4.11.0 through 4.11.2 and 4.12.0
Description The Auth0 Next.js SDK, a library for user authentication in Next.js applications, has an issue where concurrent requests from the same client can lead to incorrect lookups in the TokenRequestCache for request results.
Recommendations Update to Auth0 Next.js SDK version 4.11.3 or 4.12.1.

Exploit

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-67490
GHSA-WCGJ-F865-C7J7

Affected Products

Auth0 Next.Js Sdk