{"id":"CVE-2025-67490","aliases":["GHSA-wcgj-f865-c7j7"],"url":"https://o3.security/vulnerability/CVE-2025-67490","summary":"Auth0 Next.js SDK has Improper Request Caching Lookup","details":"### Description\nWhen using affected versions of the Next.js SDK, simultaneous requests on the same client may result in improper lookups in the TokenRequestCache for the request results.\n\n### Am I Affected?\nYou are affected if you meet the following preconditions:\n- Applications using the auth0/nextjs-auth0 SDK with a singleton client instance, versions 4.11.0, 4.11.1, and 4.12.0.\n\n### Affected product and versions\nAuth0/nextjs-auth0 v4.11.0, v4.11.1, and v4.12.0.\n\n### Resolution\nUpgrade Auth0/nextjs-auth0 version to v4.11.2 or v4.12.1\n\n### Acknowledgements\nOkta would like to thank Joshua Rogers (MegaManSec) for their discovery and responsible disclosure.","published":"2025-12-10T22:16:08.262Z","modified":"2026-08-12T03:51:43.292735830Z","cvss":{"score":5.4,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@auth0/nextjs-auth0","fixedVersion":"4.11.2"},{"ecosystem":"npm","name":"@auth0/nextjs-auth0","fixedVersion":"4.12.1"}],"fix":{"url":"https://github.com/auth0/nextjs-auth0/commit/26cc8a7c60f4b134700912736f991a25bd6bbf0b","label":"auth0/nextjs-auth0@26cc8a7"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/67xxx/CVE-2025-67490.json"},{"type":"ADVISORY","url":"https://github.com/auth0/nextjs-auth0/security/advisories/GHSA-wcgj-f865-c7j7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-67490"},{"type":"FIX","url":"https://github.com/auth0/nextjs-auth0/commit/26cc8a7c60f4b134700912736f991a25bd6bbf0b"},{"type":"PACKAGE","url":"https://github.com/auth0/nextjs-auth0"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:43.292735830Z"}}