Session Cookie Vulnerability in Auth0 Next.js SDK for User Authentication
CVE-2025-48947
What is CVE-2025-48947?
The Auth0 Next.js SDK is designed to streamline user authentication in applications built with Next.js. In versions ranging from 4.0.1 to 4.6.0, a significant vulnerability arises from __session cookies set by the auth0.middleware. This issue occurs when these cookies are improperly cached by Content Delivery Networks (CDNs), due to the absence of essential Cache-Control headers. For applications to be at risk, specific conditions must align: utilization of the aforementioned SDK versions, deployment behind a CDN that caches Set-Cookie responses, and negligence in configuring Cache-Control headers on sensitive responses. Users are strongly advised to upgrade to version 4.6.1 to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
nextjs-auth0 >= 4.0.1, < 4.6.1
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
