{"api_version":"1","generated_at":"2026-10-01T06:40:30+00:00","cve":"CVE-2025-67490","urls":{"html":"https://cve.report/CVE-2025-67490","api":"https://cve.report/api/cve/CVE-2025-67490.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2025-67490","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2025-67490"},"summary":{"title":"Auth0 Next.js SDK has Improper Request Caching Lookup","description":"The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. When using versions 4.11.0 through 4.11.2 and 4.12.0, simultaneous requests on the same client may result in improper lookups in the TokenRequestCache for the request results. This issue is fixed in versions 4.11.2 and 4.12.1.","state":"PUBLISHED","assigner":"GitHub_M","published_at":"2025-12-10 23:15:48","updated_at":"2026-09-25 23:10:00"},"problem_types":["CWE-863","CWE-863 CWE-863: Incorrect Authorization"],"metrics":[{"version":"3.1","source":"security-advisories@github.com","type":"Secondary","score":"5.4","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"NONE"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"5.4","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:N","data":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":5.4,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:N","version":"3.1"}}],"references":[{"url":"https://github.com/auth0/nextjs-auth0/security/advisories/GHSA-wcgj-f865-c7j7","name":"https://github.com/auth0/nextjs-auth0/security/advisories/GHSA-wcgj-f865-c7j7","refsource":"security-advisories@github.com","tags":["Vendor Advisory"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/auth0/nextjs-auth0/commit/26cc8a7c60f4b134700912736f991a25bd6bbf0b","name":"https://github.com/auth0/nextjs-auth0/commit/26cc8a7c60f4b134700912736f991a25bd6bbf0b","refsource":"security-advisories@github.com","tags":["Patch"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2025-67490","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-67490","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"auth0","product":"nextjs-auth0","version":"affected >= 4.12.0, < 4.12.1","platforms":[]},{"source":"CNA","vendor":"auth0","product":"nextjs-auth0","version":"affected >= 4.11.0, < 4.11.2","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2025","cve_id":"67490","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"auth0","cpe5":"nextjs-auth0","cpe6":"4.11.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"node.js","cpe12":"*","cpe13":"*"},{"cve_year":"2025","cve_id":"67490","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"auth0","cpe5":"nextjs-auth0","cpe6":"4.11.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"node.js","cpe12":"*","cpe13":"*"},{"cve_year":"2025","cve_id":"67490","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"auth0","cpe5":"nextjs-auth0","cpe6":"4.12.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"node.js","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2025","cve_id":"67490","cve":"CVE-2025-67490","epss":"0.002020000","percentile":"0.090580000","score_date":"2026-09-27","updated_at":"2026-09-28 00:02:21"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2025-67490","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2025-12-11T15:38:23.260812Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2025-12-11T15:38:34.314Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"product":"nextjs-auth0","vendor":"auth0","versions":[{"status":"affected","version":">= 4.12.0, < 4.12.1"},{"status":"affected","version":">= 4.11.0, < 4.11.2"}]}],"descriptions":[{"lang":"en","value":"The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. When using versions 4.11.0 through 4.11.2 and 4.12.0, simultaneous requests on the same client may result in improper lookups in the TokenRequestCache for the request results. This issue is fixed in versions 4.11.2 and 4.12.1."}],"metrics":[{"cvssV3_1":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":5.4,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:N","version":"3.1"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-863","description":"CWE-863: Incorrect Authorization","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2025-12-10T22:16:08.262Z","orgId":"a0819718-46f1-4df5-94e2-005712e83aaa","shortName":"GitHub_M"},"references":[{"name":"https://github.com/auth0/nextjs-auth0/security/advisories/GHSA-wcgj-f865-c7j7","tags":["x_refsource_CONFIRM"],"url":"https://github.com/auth0/nextjs-auth0/security/advisories/GHSA-wcgj-f865-c7j7"},{"name":"https://github.com/auth0/nextjs-auth0/commit/26cc8a7c60f4b134700912736f991a25bd6bbf0b","tags":["x_refsource_MISC"],"url":"https://github.com/auth0/nextjs-auth0/commit/26cc8a7c60f4b134700912736f991a25bd6bbf0b"}],"source":{"advisory":"GHSA-wcgj-f865-c7j7","discovery":"UNKNOWN"},"title":"Auth0 Next.js SDK has Improper Request Caching Lookup"}},"cveMetadata":{"assignerOrgId":"a0819718-46f1-4df5-94e2-005712e83aaa","assignerShortName":"GitHub_M","cveId":"CVE-2025-67490","datePublished":"2025-12-10T22:16:08.262Z","dateReserved":"2025-12-08T18:49:47.486Z","dateUpdated":"2025-12-11T15:38:34.314Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2025-12-10 23:15:48","lastModifiedDate":"2026-09-25 23:10:00","problem_types":["CWE-863","CWE-863 CWE-863: Incorrect Authorization"],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":4.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-12-11T15:38:23.260812Z","id":"CVE-2025-67490","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:auth0:nextjs-auth0:4.11.0:*:*:*:*:node.js:*:*","matchCriteriaId":"CBE707C0-E392-4EE7-A03A-1C25BFE5DC54"},{"vulnerable":true,"criteria":"cpe:2.3:a:auth0:nextjs-auth0:4.11.1:*:*:*:*:node.js:*:*","matchCriteriaId":"42224B81-6680-441E-B9E9-F4126CFCF2E4"},{"vulnerable":true,"criteria":"cpe:2.3:a:auth0:nextjs-auth0:4.12.0:*:*:*:*:node.js:*:*","matchCriteriaId":"480F59EF-7D13-4DCD-82B2-50596FC6FDB1"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2025","CveId":"67490","Ordinal":"1","Title":"Auth0 Next.js SDK has Improper Request Caching Lookup","CVE":"CVE-2025-67490","Year":"2025"},"notes":[{"CveYear":"2025","CveId":"67490","Ordinal":"1","NoteData":"The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. When using versions 4.11.0 through 4.11.2 and 4.12.0, simultaneous requests on the same client may result in improper lookups in the TokenRequestCache for the request results. This issue is fixed in versions 4.11.2 and 4.12.1.","Type":"Description","Title":"Auth0 Next.js SDK has Improper Request Caching Lookup"}]}}}