Improper Request Caching Lookup in the Auth0 Next.js SDK
Moderate severity GitHub Reviewed Published Dec 10, 2025 in auth0/nextjs-auth0 • Updated Dec 11, 2025
Package
@auth0/nextjs-auth0 (npm)
Affected versions
>= 4.11.0, < 4.11.2
>= 4.12.0, < 4.12.1
Patched versions
4.11.2
4.12.1
Description
Published to the GitHub Advisory Database Dec 10, 2025
Reviewed Dec 10, 2025
Published by the National Vulnerability DatabaseDec 10, 2025
Last updated Dec 11, 2025
Description
When using affected versions of the Next.js SDK, simultaneous requests on the same client may result in improper lookups in the TokenRequestCache for the request results.
Am I Affected?
You are affected if you meet the following preconditions:
Affected product and versions
Auth0/nextjs-auth0 v4.11.0, v4.11.1, and v4.12.0.
Resolution
Upgrade Auth0/nextjs-auth0 version to v4.11.2 or v4.12.1
Acknowledgements
Okta would like to thank Joshua Rogers (MegaManSec) for their discovery and responsible disclosure.
References