NextJS-Auth0 SDK Vulnerable to CDN Caching of Session Cookies
Description
Published by the National Vulnerability Database
Jun 4, 2025
Published to the GitHub Advisory Database
Jun 4, 2025
Reviewed
Jun 4, 2025
Last updated
Jun 4, 2025
Overview
In Auth0 Next.js SDK versions 4.0.1 to 4.6.0, __session cookies set by auth0.middleware may be cached by CDNs due to missing Cache-Control headers.
Am I Affected?
You are affected by this vulnerability if you meet the following preconditions:
Fix
Upgrade auth0/nextjs-auth0 to v4.6.1.
References