CVE-2025-67490EPSS p9.2%

CVE-2025-67490CVE-2025-67490

auth0 / nextjs-auth0

Description

The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. When using versions 4.11.0 through 4.11.2 and 4.12.0, simultaneous requests on the same client may result in improper lookups in the TokenRequestCache for the request results. This issue is fixed in versions 4.11.2 and 4.12.1.

Scoring

CVSS 5.4 ()
VectorCVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:N
EPSS0.20% probability of exploitation · percentile 9.2% · 2026-10-05T12:00:23Z
Last modified2026-09-25
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.