Vulnerability Details CVE-2025-67490
The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. When using versions 4.11.0 through 4.11.2 and 4.12.0, simultaneous requests on the same client may result in improper lookups in the TokenRequestCache for the request results. This issue is fixed in versions 4.11.2 and 4.12.1.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 20.7%
CVSS Severity
CVSS v3 Score 5.4
Products affected by CVE-2025-67490
-
cpe:2.3:a:auth0:nextjs-auth0:4.11.0
-
cpe:2.3:a:auth0:nextjs-auth0:4.11.1
-
cpe:2.3:a:auth0:nextjs-auth0:4.12.0