OktaOKTA-070EKHH
Improper Proxy Cache Lookup in the Auth0 Next.js SDK CVE-2026-40155 - Apr 17, 2026
UnratedCVE-2026-40155 · Published Apr 17, 2026
In affected versions of the Next.js SDK, simultaneous requests that trigger a nonce retry may cause the proxy cache fetcher to perform improper lookups for the token request results. To remediate, upgrade Auth0/nextjs-auth0 version to version 4.18.0 or greater.
Affected versions
The source does not list versions here. See the source advisory for affected products and fixes.
Details and references
More Okta advisories
All Okta| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jun 10 | Bearer Token Accepted via URL Query Parameter in Auth0 Symfony SDK CVE-2026-50157 - Jun... | Unrated | No fix yet |
| May 6 | Improper Permission Checking in Auth0.js SDK CVE-2026-42280 - May 6, 2026 | Unrated | No fix yet |
| Apr 1 | Insufficient Entropy in Cookie Encryption in Auth0 Symfony SDK CVE-2026-34236 - Apr 1... | Unrated | No fix yet |
| Dec 102025 | Improper Validation of Query Parameters in Auth0 Next.js SDK CVE-2025-67716 - Dec 10, 2025 | Unrated | No fix yet |
| Dec 102025 | Improper Request Caching Lookup in the Auth0 Next.js SDK CVE-2025-67490 - Dec 10, 2025 | Unrated | No fix yet |
| Dec 102025 | Improper Memory Cleanup in the Okta Java SDK CVE-2025-66033 - Dec 10, 2025 | Unrated | No fix yet |