next-auth
Overview
Canonical component data stored by Polaris.
4.22.5
npm
framework
1
10
Not linked
pkg:npm/[email protected]
Maintenance
Derived from available component and registry data
Medium
1094 days
Minor update available
Yes
Lifecycle
Source: endoflife.date
Registry
Source: deps.dev
npm
4.24.15
8/8/2023
8
5
Known Vulnerabilities
Source: OSV.dev
GHSA-5jpx-9hw9-2fx4
NextAuthjs Email misdelivery Vulnerability
GHSA-7rqj-j65f-68wh
Auth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass
GHSA-v64w-49xw-qq89
Possible user mocking that bypasses basic authentication
GHSA-x445-f3h2-j279
Auth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them
GHSA-xmf8-cvqr-rfgj
Auth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers
Security
Source: OpenSSF Scorecard
Systems (1)
Dependencies
10 direct dependencies