Improper Token Cache Handling in Auth0 Next.js SDK
CVE-2025-67490

5.4MEDIUM

Key Information:

Vendor

Auth0

Vendor
CVE Published:
10 December 2025

What is CVE-2025-67490?

The Auth0 Next.js SDK, utilized for user authentication within Next.js applications, contains a vulnerability that arises from improper handling of simultaneous requests. Specifically, in versions 4.11.0 through 4.11.2 and 4.12.0, concurrent requests made by the same client could lead to incorrect entries in the TokenRequestCache, potentially compromising authentication operations. The issue has been resolved in subsequent versions 4.11.2 and 4.12.1.

Affected Version(s)

nextjs-auth0 >= 4.12.0, < 4.12.1 < 4.12.0, 4.12.1

nextjs-auth0 >= 4.11.0, < 4.11.2 < 4.11.0, 4.11.2

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-67490 : Improper Token Cache Handling in Auth0 Next.js SDK