{"id":"GHSA-xq8m-7c5p-c2r6","summary":"Auth0 Next.js SDK has Improper Proxy Cache Lookup","details":"### Description\nIn affected versions of the Next.js SDK, simultaneous requests that trigger a nonce retry may cause the proxy cache fetcher to perform improper lookups for the token request results.\n\n### Which Projects are Affected?\nUsers are affected if they meet all of the following preconditions:\n- Applications using the auth0/nextjs-auth0 SDK, versions 4.12.0 to 4.17.0, and\n- Applications using the proxy handler  /me/* and /my-org/* with DPoP enabled.\n\n\n### Affected product and versions\nAuth0/nextjs-auth0 v4.12.0 to 4.17.0\n\n### Resolution\nUpgrade Auth0/nextjs-auth0 version to v4.18.0 or greater\n\n### Acknowledgements\nOkta would like to thank Reynaldo Immanuel for their discovery and responsible disclosure.","aliases":["CVE-2026-40155"],"modified":"2026-04-21T15:56:31.005142Z","published":"2026-04-21T15:21:46Z","database_specific":{"nvd_published_at":"2026-04-17T21:16:33Z","cwe_ids":["CWE-362","CWE-863"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-04-21T15:21:46Z"},"references":[{"type":"WEB","url":"https://github.com/auth0/nextjs-auth0/security/advisories/GHSA-xq8m-7c5p-c2r6"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-40155"},{"type":"WEB","url":"https://github.com/auth0/nextjs-auth0/commit/98c36dc306970c2230ea1a32efef431d29b99978"},{"type":"PACKAGE","url":"https://github.com/auth0/nextjs-auth0"},{"type":"WEB","url":"https://github.com/auth0/nextjs-auth0/releases/tag/v4.18.0"}],"affected":[{"package":{"name":"@auth0/nextjs-auth0","ecosystem":"npm","purl":"pkg:npm/%40auth0/nextjs-auth0"},"ranges":[{"type":"SEMVER","events":[{"introduced":"4.12.0"},{"fixed":"4.18.0"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 4.17.0","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-xq8m-7c5p-c2r6/GHSA-xq8m-7c5p-c2r6.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:N"}]}