{"id":"CVE-2026-73420","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-73420","summary":"Auth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass","details":"## Summary\n\nThe default email-address normalizer used by the email/magic-link sign-in flow validates the address **before** applying Unicode normalization. An address can contain a Unicode character that is not an ASCII `@` (U+0040) but canonicalizes to one under NFKC/NFKD normalization (the normalization commonly applied by mail libraries and services for internationalized email). Such an address passes the normalizer's single-`@` check, but a downstream mail library that normalizes the string then sees two `@` separators and may deliver the passwordless sign-in link to a different recipient than intended. This is an instance of validating before canonicalizing.\n\n## Am I affected?\n\nYou may be affected if **all** of the following hold:\n\n- You use `next-auth` `>= 4.0.0, < 4.24.14`, or `@auth/core` `>= 0.1.0, < 0.41.3`.\n- You have the email / magic-link (passwordless) provider enabled.\n- You rely on the built-in default identifier normalizer (you have not supplied your own `normalizeIdentifier`).\n- Your `sendVerificationRequest` implementation uses a mail library or delivery service that applies Unicode normalization to recipient addresses (most internationalized-email/SMTPUTF8-capable senders do).\n\nYou are **not** affected if you do not use the email provider, or if your normalizer/mailer rejects or canonicalizes non-ASCII addresses before they are validated.\n\n## Impact\n\n- Account takeover: an attacker who knows a victim's email address can request a magic link that is delivered to an attacker-controlled mailbox, then use it to sign in as the victim.\n- No victim interaction is required to misroute the link; the attacker initiates the flow.\n\n## Patched version\n\nThe fix applies Unicode (NFKC) normalization before the address is validated, so homoglyph separators are collapsed and rejected up front. Upgrade to the first release containing this fix (pending; this advisory will be updated with the exact patched version before publication). No application code changes are required after upgrading.\n\n## Workarounds\n\nIf you cannot upgrade immediately:\n\n- Supply a custom `normalizeIdentifier` on the email provider that calls `identifier.normalize(\"NFKC\")` (and lower-cases/trims) **before** any validation, and rejects addresses that do not contain exactly one `@` after normalization.\n- Or reject any address whose local part or domain contains non-ASCII characters, if your user base does not require internationalized email addresses.\n\n## Credit\n\nReported by @kakashi-kx. Thank you for the responsible disclosure.","published":"2026-07-23T14:40:15Z","modified":"2026-08-12T20:30:06.778226343Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"npm","name":"@auth/core","fixedVersion":"0.41.3"},{"ecosystem":"npm","name":"next-auth","fixedVersion":"4.24.15"},{"ecosystem":"npm","name":"next-auth","fixedVersion":"5.0.0-beta.32"}],"fix":{"url":"https://github.com/nextauthjs/next-auth/commit/19d2feb24359fa8c79418907fc68d9ec8152ca94","label":"nextauthjs/next-auth@19d2feb"},"references":[{"type":"WEB","url":"https://github.com/nextauthjs/next-auth/security/advisories/GHSA-7rqj-j65f-68wh"},{"type":"WEB","url":"https://github.com/nextauthjs/next-auth/commit/19d2feb24359fa8c79418907fc68d9ec8152ca94"},{"type":"WEB","url":"https://github.com/nextauthjs/next-auth/commit/a63eee12a1a20cb35209e44195b097868517b9a0"},{"type":"PACKAGE","url":"https://github.com/nextauthjs/next-auth"},{"type":"WEB","url":"https://github.com/nextauthjs/next-auth/releases/tag/@auth/core@0.41.3"},{"type":"WEB","url":"https://github.com/nextauthjs/next-auth/releases/tag/next-auth@4.24.15"},{"type":"WEB","url":"https://github.com/nextauthjs/next-auth/releases/tag/next-auth@5.0.0-beta.32"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T20:30:06.778226343Z"}}