{"api_version":"1","generated_at":"2026-08-13T05:59:13+00:00","cve":"CVE-2026-73419","urls":{"html":"https://cve.report/CVE-2026-73419","api":"https://cve.report/api/cve/CVE-2026-73419.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-73419","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-73419"},"summary":{"title":"NextAuth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them","description":"NextAuth.js provides authentication for Next.js. Prior to@auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, Auth.js stores the OAuth/OIDC anti-CSRF checks state, nonce, and the PKCE verifier in global cookies that are not bound to the provider that created them. On callback, a check value minted during a sign-in started with one provider can satisfy the callback for a different provider because the stored cookie is not verified against the callback provider's identity, including the provider ID, issuer, client ID, or redirect URI. In a multi-provider application that permits account linking while logged in, when one provider's authorization request is observable and a target provider callback can be satisfied without a PKCE verifier, an attacker can lure a victim into starting a legitimate same-origin flow and link the attacker's target-provider account to the victim's Auth.js user. The linked provider grants the attacker persistent sign-in to the victim's account, while cross-site request forgery alone is insufficient. This issue is fixed in @auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32.","state":"PUBLISHED","assigner":"GitHub_M","published_at":"2026-08-12 21:17:41","updated_at":"2026-08-12 21:17:41"},"problem_types":["CWE-345","CWE-346","CWE-940","CWE-345 CWE-345: Insufficient Verification of Data Authenticity","CWE-346 CWE-346: Origin Validation Error","CWE-940 CWE-940: Improper Verification of Source of a Communication Channel"],"metrics":[{"version":"3.1","source":"security-advisories@github.com","type":"Secondary","score":"6.8","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N","baseScore":6.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"6.8","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N","data":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":6.8,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N","version":"3.1"}}],"references":[{"url":"https://github.com/nextauthjs/next-auth/releases/tag/next-auth@5.0.0-beta.32","name":"https://github.com/nextauthjs/next-auth/releases/tag/next-auth@5.0.0-beta.32","refsource":"security-advisories@github.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/nextauthjs/next-auth/commit/9f7a97fade9b1319bb9ac19fc9828d62e0a2a852","name":"https://github.com/nextauthjs/next-auth/commit/9f7a97fade9b1319bb9ac19fc9828d62e0a2a852","refsource":"security-advisories@github.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/nextauthjs/next-auth/pull/13469","name":"https://github.com/nextauthjs/next-auth/pull/13469","refsource":"security-advisories@github.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/nextauthjs/next-auth/releases/tag/@auth/core@0.41.3","name":"https://github.com/nextauthjs/next-auth/releases/tag/@auth/core@0.41.3","refsource":"security-advisories@github.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/nextauthjs/next-auth/commit/5bca2399a79ba8d116ca5179b4b1ebcd152e7f05","name":"https://github.com/nextauthjs/next-auth/commit/5bca2399a79ba8d116ca5179b4b1ebcd152e7f05","refsource":"security-advisories@github.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/nextauthjs/next-auth/releases/tag/next-auth@4.24.15","name":"https://github.com/nextauthjs/next-auth/releases/tag/next-auth@4.24.15","refsource":"security-advisories@github.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/nextauthjs/next-auth/security/advisories/GHSA-x445-f3h2-j279","name":"https://github.com/nextauthjs/next-auth/security/advisories/GHSA-x445-f3h2-j279","refsource":"security-advisories@github.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-73419","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-73419","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"nextauthjs","product":"next-auth","version":"affected < 4.24.15","platforms":[]},{"source":"CNA","vendor":"nextauthjs","product":"next-auth","version":"affected >= 5.0.0-beta.4, < 5.0.0-beta.32","platforms":[]},{"source":"CNA","vendor":"@auth","product":"core","version":"affected < 0.41.3","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"product":"next-auth","vendor":"nextauthjs","versions":[{"status":"affected","version":"< 4.24.15"},{"status":"affected","version":">= 5.0.0-beta.4, < 5.0.0-beta.32"}]},{"product":"core","vendor":"@auth","versions":[{"status":"affected","version":"< 0.41.3"}]}],"descriptions":[{"lang":"en","value":"NextAuth.js provides authentication for Next.js. Prior to@auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, Auth.js stores the OAuth/OIDC anti-CSRF checks state, nonce, and the PKCE verifier in global cookies that are not bound to the provider that created them. On callback, a check value minted during a sign-in started with one provider can satisfy the callback for a different provider because the stored cookie is not verified against the callback provider's identity, including the provider ID, issuer, client ID, or redirect URI. In a multi-provider application that permits account linking while logged in, when one provider's authorization request is observable and a target provider callback can be satisfied without a PKCE verifier, an attacker can lure a victim into starting a legitimate same-origin flow and link the attacker's target-provider account to the victim's Auth.js user. The linked provider grants the attacker persistent sign-in to the victim's account, while cross-site request forgery alone is insufficient. This issue is fixed in @auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32."}],"metrics":[{"cvssV3_1":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":6.8,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N","version":"3.1"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-345","description":"CWE-345: Insufficient Verification of Data Authenticity","lang":"en","type":"CWE"}]},{"descriptions":[{"cweId":"CWE-346","description":"CWE-346: Origin Validation Error","lang":"en","type":"CWE"}]},{"descriptions":[{"cweId":"CWE-940","description":"CWE-940: Improper Verification of Source of a Communication Channel","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-08-12T20:23:39.174Z","orgId":"a0819718-46f1-4df5-94e2-005712e83aaa","shortName":"GitHub_M"},"references":[{"name":"https://github.com/nextauthjs/next-auth/security/advisories/GHSA-x445-f3h2-j279","tags":["x_refsource_CONFIRM"],"url":"https://github.com/nextauthjs/next-auth/security/advisories/GHSA-x445-f3h2-j279"},{"name":"https://github.com/nextauthjs/next-auth/pull/13469","tags":["x_refsource_MISC"],"url":"https://github.com/nextauthjs/next-auth/pull/13469"},{"name":"https://github.com/nextauthjs/next-auth/commit/5bca2399a79ba8d116ca5179b4b1ebcd152e7f05","tags":["x_refsource_MISC"],"url":"https://github.com/nextauthjs/next-auth/commit/5bca2399a79ba8d116ca5179b4b1ebcd152e7f05"},{"name":"https://github.com/nextauthjs/next-auth/commit/9f7a97fade9b1319bb9ac19fc9828d62e0a2a852","tags":["x_refsource_MISC"],"url":"https://github.com/nextauthjs/next-auth/commit/9f7a97fade9b1319bb9ac19fc9828d62e0a2a852"},{"name":"https://github.com/nextauthjs/next-auth/releases/tag/@auth/core@0.41.3","tags":["x_refsource_MISC"],"url":"https://github.com/nextauthjs/next-auth/releases/tag/@auth/core@0.41.3"},{"name":"https://github.com/nextauthjs/next-auth/releases/tag/next-auth@4.24.15","tags":["x_refsource_MISC"],"url":"https://github.com/nextauthjs/next-auth/releases/tag/next-auth@4.24.15"},{"name":"https://github.com/nextauthjs/next-auth/releases/tag/next-auth@5.0.0-beta.32","tags":["x_refsource_MISC"],"url":"https://github.com/nextauthjs/next-auth/releases/tag/next-auth@5.0.0-beta.32"}],"source":{"advisory":"GHSA-x445-f3h2-j279","discovery":"UNKNOWN"},"title":"NextAuth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them"}},"cveMetadata":{"assignerOrgId":"a0819718-46f1-4df5-94e2-005712e83aaa","assignerShortName":"GitHub_M","cveId":"CVE-2026-73419","datePublished":"2026-08-12T20:23:39.174Z","dateReserved":"2026-08-12T14:32:11.795Z","dateUpdated":"2026-08-12T20:23:39.174Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-12 21:17:41","lastModifiedDate":"2026-08-12 21:17:41","problem_types":["CWE-345","CWE-346","CWE-940","CWE-345 CWE-345: Insufficient Verification of Data Authenticity","CWE-346 CWE-346: Origin Validation Error","CWE-940 CWE-940: Improper Verification of Source of a Communication Channel"],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N","baseScore":6.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":5.2}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"73419","Ordinal":"1","Title":"NextAuth.js: OAuth state, nonce, and PKCE check cookies are not ","CVE":"CVE-2026-73419","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"73419","Ordinal":"1","NoteData":"NextAuth.js provides authentication for Next.js. Prior to@auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, Auth.js stores the OAuth/OIDC anti-CSRF checks state, nonce, and the PKCE verifier in global cookies that are not bound to the provider that created them. On callback, a check value minted during a sign-in started with one provider can satisfy the callback for a different provider because the stored cookie is not verified against the callback provider's identity, including the provider ID, issuer, client ID, or redirect URI. In a multi-provider application that permits account linking while logged in, when one provider's authorization request is observable and a target provider callback can be satisfied without a PKCE verifier, an attacker can lure a victim into starting a legitimate same-origin flow and link the attacker's target-provider account to the victim's Auth.js user. The linked provider grants the attacker persistent sign-in to the victim's account, while cross-site request forgery alone is insufficient. This issue is fixed in @auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32.","Type":"Description","Title":"NextAuth.js: OAuth state, nonce, and PKCE check cookies are not "}]}}}