vciy

CVEs we hold for Auth0

Records whose assigning authority named Auth0 as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-85983Local Privilege Escalation in Auth0 AD/LDAP ConnectorAuth0 AD/LDAP Connector
CVE-2026-85982Stored Cross-Site Scripting (XSS) in Auth0 AD/LDAP ConnectorAuth0 AD/LDAP Connector
CVE-2026-85981Unauthenticated Localhost Admin Panel in Auth0 AD/LDAP ConnectorAuth0 AD/LDAP Connector
CVE-2026-84685Improper Cache Isolation in auth0/react-native-auth0 SDK Web Platform Credential ManagementAuth0 react-native-auth0
CVE-2026-50157Auth0 Symfony: Bearer Token Accepted via URL Query Parameter in Auth0 Symfony SDKauth0 symfony
CVE-2026-42280Improper Permission Checking in Auth.js SDKauth0 auth0.js
CVE-2026-40155Auth0 Next.js SDK has Improper Proxy Cache Lookupauth0 nextjs-auth0
CVE-2026-34236Auth0 PHP SDK Insufficient Entropy in Cookie Encryptionauth0-PHP
CVE-2025-68129Auth0-PHP SDK has Improper Audience Validationauth0-PHP
CVE-2025-67716Auth0 Next.js SDK has Improper Validation of Query Parametersauth0 nextjs-auth0
CVE-2025-67490Auth0 Next.js SDK has Improper Request Caching Lookupauth0 nextjs-auth0
CVE-2025-65945auth0/node-jws improper HMAC signature verification vulnerabilityauth0 node-jws
CVE-2025-58769auth0-PHP: Improper File Type Handling in Bulk User Importauth0 laravel-auth0
CVE-2025-48951Auth0-PHP SDK Deserialization of Untrusted Data vulnerabilityauth0-PHP
CVE-2025-48947NextJS-Auth0 SDK Vulnerable to CDN Caching of Session Cookiesauth0 nextjs-auth0
CVE-2025-47275Brute Force Authentication Tags of CookieStore Sessions in Auth0-PHP SDKauth0-PHP
CVE-2025-46573passport-wsfed-saml2 Has SAML Authentication Bypass via Attribute Smugglingauth0 passport-wsfed-saml2
CVE-2025-46572passport-wsfed-saml2 Has SAML Authentication Bypass via Signature Wrappingauth0 passport-wsfed-saml2
CVE-2025-46345Auth0 Account Link Extension JWT Invalid Signature Validationauth0-extensions auth0-account-link-extension
CVE-2025-46344Auth0 NextJS SDK v4 Missing Session Invalidationauth0 nextjs-auth0
CVE-2023-6813Login by Auth0 <= 4.6.0 - Reflected Cross-Site Scripting via wleAuth0
CVE-2022-29172HTML injection with additional signup fieldsauth0 lock
CVE-2022-24794Open Redirect in express-openid-connectauth0 express-openid-connect
CVE-2022-23541jsonwebtoken's insecure implementation of key retrieval function could lead to Forgeable Public/Private Tokens from RSA…auth0 node-jsonwebtoken
CVE-2022-23540jsonwebtoken vulnerable to signature validation bypass due to insecure default algorithm in jwt.verify()auth0 node-jsonwebtoken
CVE-2022-23539jsonwebtoken unrestricted key type could lead to legacy keys usageauth0 node-jsonwebtoken
CVE-2022-23505Passport-wsfed-saml2 vulnerable to Authentication Bypass for WSFed authenticationauth0 passport-wsfed-saml2
CVE-2021-43812Open redirect in nextjs-auth0auth0 nextjs-auth0
CVE-2021-41246Session fixation in express-openid-connectauth0 express-openid-connect
CVE-2021-32702Reflected XSS from the callback handler's error query parameterauth0 nextjs-auth0
CVE-2021-32641Reflected XSS when using flashMessagesauth0 lock
CVE-2020-5263Information disclosure through error objectauth0 auth0.js
CVE-2020-15259CSRF in Auth0 ad-ldap-connectorauth0 ad-ldap-connector
CVE-2020-15240Regression in JWT Signature Validationauth0 omniauth-auth0
CVE-2020-15125Authorization header is not sanitized in an error object in auth0auth0 node-auth0
CVE-2020-15119DOM-based XSS in auth0-lockauth0 lock
CVE-2020-15084Authorization bypass in express-jwtauth0 express-jwt

37 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.