{"id":"CVE-2026-40155","aliases":["GHSA-xq8m-7c5p-c2r6"],"url":"https://o3.security/vulnerability/CVE-2026-40155","summary":"Auth0 Next.js SDK has Improper Proxy Cache Lookup","details":"### Description\nIn affected versions of the Next.js SDK, simultaneous requests that trigger a nonce retry may cause the proxy cache fetcher to perform improper lookups for the token request results.\n\n### Which Projects are Affected?\nUsers are affected if they meet all of the following preconditions:\n- Applications using the auth0/nextjs-auth0 SDK, versions 4.12.0 to 4.17.0, and\n- Applications using the proxy handler  /me/* and /my-org/* with DPoP enabled.\n\n\n### Affected product and versions\nAuth0/nextjs-auth0 v4.12.0 to 4.17.0\n\n### Resolution\nUpgrade Auth0/nextjs-auth0 version to v4.18.0 or greater\n\n### Acknowledgements\nOkta would like to thank Reynaldo Immanuel for their discovery and responsible disclosure.","published":"2026-04-17T20:54:38.958Z","modified":"2026-08-12T03:51:30.974102489Z","cvss":{"score":5.4,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:N"},"epss":{"score":0.00214,"percentile":0.11633,"asOf":"2026-08-25"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@auth0/nextjs-auth0","fixedVersion":"4.18.0"}],"fix":{"url":"https://github.com/auth0/nextjs-auth0/commit/98c36dc306970c2230ea1a32efef431d29b99978","label":"auth0/nextjs-auth0@98c36dc"},"references":[{"type":"WEB","url":"https://github.com/auth0/nextjs-auth0/releases/tag/v4.18.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/40xxx/CVE-2026-40155.json"},{"type":"ADVISORY","url":"https://github.com/auth0/nextjs-auth0/security/advisories/GHSA-xq8m-7c5p-c2r6"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-40155"},{"type":"FIX","url":"https://github.com/auth0/nextjs-auth0/commit/98c36dc306970c2230ea1a32efef431d29b99978"},{"type":"PACKAGE","url":"https://github.com/auth0/nextjs-auth0"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:30.974102489Z"}}