{"id":"CVE-2025-46344","aliases":["GHSA-pjr6-jx7r-j4r6"],"url":"https://o3.security/vulnerability/CVE-2025-46344","summary":"Auth0 NextJS SDK v4 Missing Session Invalidation","details":"The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. Versions starting from 4.0.1 and prior to 4.5.1, do not invoke `.setExpirationTime` when generating a JWE token for the session. As a result, the JWE does not contain an internal expiration claim. While the session cookie may expire or be cleared, the JWE remains valid. This issue has been patched in version 4.5.1.","published":"2025-04-29T20:43:41.538Z","modified":"2026-08-12T03:51:18.794487400Z","cvss":null,"epss":{"score":0.00413,"percentile":0.34059,"asOf":"2026-08-24"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@auth0/nextjs-auth0","fixedVersion":"4.5.1"}],"fix":{"url":"https://github.com/auth0/nextjs-auth0/commit/a4f061aed02ffa132feca8adfbd11704df17e1c3","label":"auth0/nextjs-auth0@a4f061a"},"references":[{"type":"WEB","url":"https://github.com/auth0/nextjs-auth0/releases/tag/v4.5.1"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/46xxx/CVE-2025-46344.json"},{"type":"ADVISORY","url":"https://github.com/auth0/nextjs-auth0/security/advisories/GHSA-pjr6-jx7r-j4r6"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-46344"},{"type":"FIX","url":"https://github.com/auth0/nextjs-auth0/commit/a4f061aed02ffa132feca8adfbd11704df17e1c3"},{"type":"PACKAGE","url":"https://github.com/auth0/nextjs-auth0"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:18.794487400Z"}}