Vulnerabilities/

authkit-nextjs may let session cookies be cached in CDNs

Severity:
High

Description

In authkit-nextjs version 2.11.0 and below, authenticated responses do not defensively apply anti-caching headers. In environments where CDN caching is enabled, this can result in session tokens being included in cached responses and subsequently served to multiple users.

Next.

Recommendation

Update the @workos-inc/authkit-nextjs package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@workos-inc/authkit-nextjs
Anything's wrong? Let us know Last updated on November 21, 2025