{"api_version":"v1","generated_at":"2026-10-06T06:25:00+00:00","product":{"cve_count":7,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-auth0-nextjs-auth0-e5b74a030f47","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"nextjs-auth0","next_cursor":null,"observations":[{"affected":">= 4.12.0, < 4.18.0","affected_versions_present":true,"cve_id":"CVE-2026-40155","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-40155","fixed":"4.18.0.","last_modified":"2026-04-20T14:57:32.023Z","patch_url":"https://github.com/auth0/nextjs-auth0/commit/98c36dc306970c2230ea1a32efef431d29b99978","primary_source":"","published":"2026-04-17T20:54:38.958Z"},{"affected":">= 4.9.0, < 4.13.0","affected_versions_present":true,"cve_id":"CVE-2025-67716","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-67716","fixed":"4.13.0.","last_modified":"2025-12-11T16:09:34.320Z","patch_url":"https://github.com/auth0/nextjs-auth0/commit/35eb321de3345ccf23e8c0d6f66c9f2f2f57d26c","primary_source":"","published":"2025-12-11T00:21:27.687Z"},{"affected":"nextjs-auth0: >= 4.12.0, < 4.12.1, >= 4.11.0, < 4.11.2","affected_versions_present":true,"cve_id":"CVE-2025-67490","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-67490","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-12-11T15:38:34.314Z","patch_url":"https://github.com/auth0/nextjs-auth0/commit/26cc8a7c60f4b134700912736f991a25bd6bbf0b","primary_source":"","published":"2025-12-10T22:16:08.262Z"},{"affected":">= 4.0.1, < 4.6.1","affected_versions_present":true,"cve_id":"CVE-2025-48947","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-48947","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-06-04T20:50:02.568Z","patch_url":"","primary_source":"","published":"2025-06-04T20:14:44.369Z"},{"affected":">= 4.0.1, < 4.5.1","affected_versions_present":true,"cve_id":"CVE-2025-46344","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-46344","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-04-30T13:17:43.169Z","patch_url":"","primary_source":"","published":"2025-04-29T20:43:41.538Z"},{"affected":"< 1.6.2","affected_versions_present":true,"cve_id":"CVE-2021-43812","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-43812","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-04T04:03:08.682Z","patch_url":"https://github.com/auth0/nextjs-auth0/commit/0bbd9f8a0c93af51f607f28633b5fb18c5e48ad6","primary_source":"","published":"2021-12-16T18:20:12.000Z"},{"affected":"< 1.4.2","affected_versions_present":true,"cve_id":"CVE-2021-32702","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-32702","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-03T23:25:31.131Z","patch_url":"https://github.com/auth0/nextjs-auth0/commit/6996e2528ceed98627caa28abafbc09e90163ccf","primary_source":"","published":"2021-06-25T16:25:11.000Z"}],"source_generated_at":"2026-10-05T06:20:29.126Z","vendor":"auth0"}}
