next-auth vulnerabilities

Authentication for Next.js

  • latest version

    4.24.11

  • latest non vulnerable version

  • first published

    7 years ago

  • latest version published

    10 months ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the next-auth package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Improper Authorization

    <4.24.5
    • M
    Session Fixation

    <4.20.1
    • M
    Improper Authentication

    <4.12.0
    • C
    Improper Authorization

    <3.29.10>=4.10.0 <4.10.3
    • L
    Information Exposure

    <3.29.9>=4.0.0 <4.10.2
    • H
    Improper Input Validation

    <3.29.8>=4.0.0 <4.9.0
    • H
    Denial of Service (DoS)

    <3.29.5>=4.0.0 <4.5.0
    • M
    Open Redirect

    <3.29.3>=4.0.0-next.1 <4.3.4
    • M
    Open Redirect

    <4.3.2
    • C
    Improper Access Control

    <3.3.0

    Package versions

    719 VERSIONS IN TOTAL See all versions
    versionpublisheddirect vulnerabilities
    5.0.0-beta.2922 Jun, 2025
    • 0
      C
    • 0
      H
    • 0
      M
    • 0
      L
    5.0.0-beta.2810 May, 2025
    • 0
      C
    • 0
      H
    • 0
      M
    • 0
      L
    5.0.0-beta.2724 Apr, 2025
    • 0
      C
    • 0
      H
    • 0
      M
    • 0
      L
    5.0.0-beta.2620 Apr, 2025
    • 0
      C
    • 0
      H
    • 0
      M
    • 0
      L
    5.0.0-beta.2519 Oct, 2024
    • 0
      C
    • 0
      H
    • 0
      M
    • 0
      L
    5.0.0-beta.2419 Oct, 2024
    • 0
      C
    • 0
      H
    • 0
      M
    • 0
      L
    5.0.0-beta.2318 Oct, 2024
    • 0
      C
    • 0
      H
    • 0
      M
    • 0
      L
    5.0.0-beta.2227 Sep, 2024
    • 0
      C
    • 0
      H
    • 0
      M
    • 0
      L
    5.0.0-beta.2115 Sep, 2024
    • 0
      C
    • 0
      H
    • 0
      M
    • 0
      L
    5.0.0-beta.2028 Jul, 2024
    • 0
      C
    • 0
      H
    • 0
      M
    • 0
      L