CVE DATABASE / CVE-2025-46344
CVE-2025-46344
Summary
The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. Versions starting from 4.0.1 and prior to 4.5.1, do not invoke `.setExpirationTime` when generating a JWE token for the session. As a result, the JWE does not contain an internal expiration claim. While the session cookie may expire or be cleared, the JWE remains valid. This issue has been patched in version 4.5.1.
Weakness type (CWE)
Check this CVE live
Use our free CVE Lookup tool for the latest NVD record, or browse the full CISA KEV catalog.
References
- https://github.com/auth0/nextjs-auth0/commit/a4f061aed02ffa132feca8adfbd11704df17e1c3
- https://github.com/auth0/nextjs-auth0/releases/tag/v4.5.1
- https://github.com/auth0/nextjs-auth0/security/advisories/GHSA-pjr6-jx7r-j4r6
Data: NIST NVD. NVD last modified 2026-04-15. Always verify against the vendor advisory before acting.