{"id":"GHSA-wcgj-f865-c7j7","summary":"Improper Request Caching Lookup in the Auth0 Next.js SDK","details":"### Description\nWhen using affected versions of the Next.js SDK, simultaneous requests on the same client may result in improper lookups in the TokenRequestCache for the request results.\n\n### Am I Affected?\nYou are affected if you meet the following preconditions:\n- Applications using the auth0/nextjs-auth0 SDK with a singleton client instance, versions 4.11.0, 4.11.1, and 4.12.0.\n\n### Affected product and versions\nAuth0/nextjs-auth0 v4.11.0, v4.11.1, and v4.12.0.\n\n### Resolution\nUpgrade Auth0/nextjs-auth0 version to v4.11.2 or v4.12.1\n\n### Acknowledgements\nOkta would like to thank Joshua Rogers (MegaManSec) for their discovery and responsible disclosure.","aliases":["CVE-2025-67490"],"modified":"2025-12-11T16:22:30.784670Z","published":"2025-12-10T21:31:24Z","database_specific":{"nvd_published_at":"2025-12-10T23:15:48Z","cwe_ids":["CWE-863"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2025-12-10T21:31:24Z"},"references":[{"type":"WEB","url":"https://github.com/auth0/nextjs-auth0/security/advisories/GHSA-wcgj-f865-c7j7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-67490"},{"type":"WEB","url":"https://github.com/auth0/nextjs-auth0/commit/26cc8a7c60f4b134700912736f991a25bd6bbf0b"},{"type":"PACKAGE","url":"https://github.com/auth0/nextjs-auth0"}],"affected":[{"package":{"name":"@auth0/nextjs-auth0","ecosystem":"npm","purl":"pkg:npm/%40auth0/nextjs-auth0"},"ranges":[{"type":"SEMVER","events":[{"introduced":"4.11.0"},{"fixed":"4.11.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/12/GHSA-wcgj-f865-c7j7/GHSA-wcgj-f865-c7j7.json"}},{"package":{"name":"@auth0/nextjs-auth0","ecosystem":"npm","purl":"pkg:npm/%40auth0/nextjs-auth0"},"ranges":[{"type":"SEMVER","events":[{"introduced":"4.12.0"},{"fixed":"4.12.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/12/GHSA-wcgj-f865-c7j7/GHSA-wcgj-f865-c7j7.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:N"}]}