CVE-2025-67490: AUTH0 Nextjs-AUTH0

Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.

The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. When using versions 4.11.0 through 4.11.2 and 4.12.0, simultaneous requests on the same client may result in improper lookups in the TokenRequestCache for the request results. This issue is fixed in versions 4.11.2 and 4.12.1.

Affected products

  • AUTH0 Nextjs-AUTH0: version 4.11.0 only; version 4.11.1 only; version 4.12.0 only

Published 2025-12-10. Last modified 2026-09-25.