Vulnerabilities/

NextJS-Auth0 SDK Vulnerable to CDN Caching of Session Cookies

Severity:
High

Description

Overview In Auth0 Next.js SDK versions 4.0.1 to 4.6.0, __session cookies set by auth0.middleware may be cached by CDNs due to missing Cache-Control headers.

Recommendation

Update the @auth0/nextjs-auth0 package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@auth0/nextjs-auth0
Anything's wrong? Let us know Last updated on June 04, 2025

This issue is available in SmartScanner Professional

See Pricing