CVE-2025-67490

The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. When using versions 4.11.0 through 4.11.2 and 4.12.0, simultaneous requests on the same client may result in improper lookups in the TokenRequestCache for the request results. This issue is fixed in versions 4.11.2 and 4.12.1.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:auth0:nextjs-auth0:4.11.0:*:*:*:*:node.js:*:*
cpe:2.3:a:auth0:nextjs-auth0:4.11.1:*:*:*:*:node.js:*:*
cpe:2.3:a:auth0:nextjs-auth0:4.12.0:*:*:*:*:node.js:*:*

History

06 Mar 2026, 19:39

Type Values Removed Values Added
CPE cpe:2.3:a:auth0:nextjs-auth0:4.11.1:*:*:*:*:node.js:*:*
cpe:2.3:a:auth0:nextjs-auth0:4.12.0:*:*:*:*:node.js:*:*
cpe:2.3:a:auth0:nextjs-auth0:4.11.0:*:*:*:*:node.js:*:*
References () https://github.com/auth0/nextjs-auth0/commit/26cc8a7c60f4b134700912736f991a25bd6bbf0b - () https://github.com/auth0/nextjs-auth0/commit/26cc8a7c60f4b134700912736f991a25bd6bbf0b - Patch
References () https://github.com/auth0/nextjs-auth0/security/advisories/GHSA-wcgj-f865-c7j7 - () https://github.com/auth0/nextjs-auth0/security/advisories/GHSA-wcgj-f865-c7j7 - Vendor Advisory
First Time Auth0 nextjs-auth0
Auth0

10 Dec 2025, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-10 23:15

Updated : 2026-03-06 19:39


NVD link : CVE-2025-67490

Mitre link : CVE-2025-67490

CVE.ORG link : CVE-2025-67490


JSON object : View

Products Affected

auth0

  • nextjs-auth0
CWE
CWE-863

Incorrect Authorization