Vulnerabilidades em Auth0
36 resultadosAnálise Vexday
Auth0 apresenta volume reduzido de vulnerabilidades (4 CVEs), com apenas 1 crítica registrada e nenhuma sob exploração ativa conhecida. O risco atual é moderado, porém relevante pelo fato de todas as 4 vulnerabilidades terem sido publicadas nos últimos 90 dias, indicando descobertas recentes, predominantemente relacionadas a falhas de autenticação/autorização (CWE-306).
CVE-2025-68129MEDIUMAuth0-PHP SDK has Improper Audience ValidationEPSS 0.4%CVE-2025-46344MEDIUMAuth0 NextJS SDK v4 Missing Session InvalidationEPSS 0.4%CVE-2025-46572CRITICALpassport-wsfed-saml2 Has SAML Authentication Bypass via Signature WrappingEPSS 0.4%CVE-2023-6813MEDIUMLogin by Auth0 <= 4.6.0 - Reflected Cross-Site Scripting via wleEPSS 0.4%CVE-2025-46573HIGHpassport-wsfed-saml2 Has SAML Authentication Bypass via Attribute SmugglingEPSS 0.4%CVE-2025-58769LOWauth0-PHP: Improper File Type Handling in Bulk User ImportEPSS 0.4%CVE-2025-67716MEDIUMAuth0 Next.js SDK has Improper Validation of Query ParametersEPSS 0.3%CVE-2026-34236HIGHAuth0 PHP SDK Insufficient Entropy in Cookie EncryptionEPSS 0.2%CVE-2026-85982CRITICALStored Cross-Site Scripting (XSS) in Auth0 AD/LDAP ConnectorEPSS 0.2%CVE-2025-65945HIGHauth0/node-jws improper HMAC signature verification vulnerabilityEPSS 0.2%CVE-2026-40155MEDIUMAuth0 Next.js SDK has Improper Proxy Cache LookupEPSS 0.2%CVE-2026-42280HIGHImproper Permission Checking in Auth.js SDKEPSS 0.2%CVE-2025-67490MEDIUMAuth0 Next.js SDK has Improper Request Caching LookupEPSS 0.2%CVE-2026-84685MEDIUMImproper Cache Isolation in auth0/react-native-auth0 SDK Web Platform Credential ManagementEPSS 0.2%CVE-2026-85983HIGHLocal Privilege Escalation in Auth0 AD/LDAP ConnectorEPSS 0.1%CVE-2026-85981MEDIUMUnauthenticated Localhost Admin Panel in Auth0 AD/LDAP ConnectorEPSS 0.1%