镜像站点 · 本页由第三方 GitHub 只读镜像提供,非 GitHub 官方站点,不接受任何登录或凭据输入。前往 github.com
Skip to content

chore(deps): update dependency @auth/core to v0.41.3 [security] - #8595

Open
renovate[bot] wants to merge 2 commits into
mainfrom
renovate/npm-auth-core-vulnerability
Open

renovate[bot] wants to merge 2 commits into
mainfrom
renovate/npm-auth-core-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
@auth/core (source) 0.41.1 → 0.41.3 age confidence

Auth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them

CVE-2026-73419 / GHSA-x445-f3h2-j279

More information

Details

Summary

Auth.js stores the OAuth/OIDC anti-CSRF checks (state, nonce, and the PKCE verifier) in global cookies that are not bound to the provider that created them. On callback, a check value minted during a sign-in started with one provider can satisfy the callback for a different provider, because the stored cookie is not verified against the callback provider's identity (provider id, issuer, client id, or redirect URI). In a multi-provider app that allows account linking while logged in, this provider-confusion / mix-up condition can let an attacker link their account at a second provider to a victim's user.

Am I affected?

You may be affected if all of the following hold:

  • You use next-auth <= 4.24.14 or >= 5.0.0-beta.1, <= 5.0.0-beta.31, or @auth/core <= 0.41.2.
  • You configure multiple OAuth/OIDC providers.
  • You allow users to link additional providers while logged in.
  • At least one configured provider's authorization request is observable by an attacker, and at least one target provider's callback can be satisfied without a PKCE verifier (i.e. it relies only on state or only on nonce).

You are not affected if you use a single OAuth provider, do not allow logged-in account linking, or all providers enforce PKCE.

Impact
  • Account-linking confusion: an attacker can get their account at a target provider linked to the victim's Auth.js user, granting the attacker persistent sign-in to the victim's account through that linked provider.
  • Exploitation requires luring the victim into starting a legitimate same-origin flow; it cannot be performed by cross-site request forgery alone, which reduces practical likelihood.
Patched version

The fix binds the OAuth check cookies to the provider/authorization flow that created them, so a callback cannot consume a check value minted for a different provider. Upgrade to the first releases containing this fix (pending; this advisory will be updated with exact patched versions before publication).

Workarounds

If you cannot upgrade immediately:

  • Enable PKCE (checks: ["pkce"], in addition to state/nonce) on every provider that supports it; PKCE blocks the practical code-swap variant because the attacker cannot observe the relying party's verifier.
  • Avoid offering logged-in account linking across multiple providers where one provider is lower-trust or attacker-observable.
  • Treat events.linkAccount as sensitive: add audit logging, user notification, or out-of-band confirmation so that any unexpected link is visible (defense-in-depth, not a root-cause fix).
Credit

Reported by @​Nadav0077. Thank you for the responsible disclosure.

Severity

  • CVSS Score: 6.8 / 10 (Medium)
  • Vector String: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Auth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @​ bypass

CVE-2026-73420 / GHSA-7rqj-j65f-68wh

More information

Details

Summary

The default email-address normalizer used by the email/magic-link sign-in flow validates the address before applying Unicode normalization. An address can contain a Unicode character that is not an ASCII @ (U+0040) but canonicalizes to one under NFKC/NFKD normalization (the normalization commonly applied by mail libraries and services for internationalized email). Such an address passes the normalizer's single-@ check, but a downstream mail library that normalizes the string then sees two @ separators and may deliver the passwordless sign-in link to a different recipient than intended. This is an instance of validating before canonicalizing.

Am I affected?

You may be affected if all of the following hold:

  • You use next-auth >= 4.0.0, < 4.24.14, or @auth/core >= 0.1.0, < 0.41.3.
  • You have the email / magic-link (passwordless) provider enabled.
  • You rely on the built-in default identifier normalizer (you have not supplied your own normalizeIdentifier).
  • Your sendVerificationRequest implementation uses a mail library or delivery service that applies Unicode normalization to recipient addresses (most internationalized-email/SMTPUTF8-capable senders do).

You are not affected if you do not use the email provider, or if your normalizer/mailer rejects or canonicalizes non-ASCII addresses before they are validated.

Impact
  • Account takeover: an attacker who knows a victim's email address can request a magic link that is delivered to an attacker-controlled mailbox, then use it to sign in as the victim.
  • No victim interaction is required to misroute the link; the attacker initiates the flow.
Patched version

The fix applies Unicode (NFKC) normalization before the address is validated, so homoglyph separators are collapsed and rejected up front. Upgrade to the first release containing this fix (pending; this advisory will be updated with the exact patched version before publication). No application code changes are required after upgrading.

Workarounds

If you cannot upgrade immediately:

  • Supply a custom normalizeIdentifier on the email provider that calls identifier.normalize("NFKC") (and lower-cases/trims) before any validation, and rejects addresses that do not contain exactly one @ after normalization.
  • Or reject any address whose local part or domain contains non-ASCII characters, if your user base does not require internationalized email addresses.
Credit

Reported by @​kakashi-kx. Thank you for the responsible disclosure.

Severity

  • CVSS Score: 9.1 / 10 (Critical)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Auth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers

CVE-2026-73418 / GHSA-xmf8-cvqr-rfgj

More information

Details

Summary

The exported getToken() helper (next-auth/jwt and @auth/core/jwt) can throw an uncaught exception when it reads a malformed Authorization: Bearer … header. When no session cookie is present, getToken() URL-decodes the bearer value before validating it, and malformed percent-encoding causes the decode step to throw rather than being treated as an invalid token. Because getToken() is commonly called in API routes, middleware, and other request handlers, a single unauthenticated request can trigger an unhandled exception in code paths that authenticate requests.

Am I affected?

You are affected if all of the following hold:

  • You use next-auth <= 5.0.0-beta.25 (or @auth/core exposing the same getToken() implementation).
  • Your application calls getToken() directly — for example in a Route Handler, middleware, or server-side request handler.
  • You do not wrap that getToken() call in your own try/catch.

You are not affected if you only use the framework's auth() helper and never call getToken() yourself, or if every getToken() call site already has its own exception handling.

Impact
  • Denial of service: an unauthenticated request carrying a malformed Bearer authorization header can raise an unhandled exception in any handler that calls getToken().
  • The impact is per-request and limited to availability; it does not expose tokens, sessions, or other data, and does not bypass authentication.

CWE-20: Improper Input Validation.

Patched version

The fix makes getToken() treat a malformed Bearer value as an invalid token and return null, matching how other undecodable tokens are already handled. Upgrade to the first release containing this fix (to be published; this advisory will be updated with the exact patched version before publication) and no code changes are required.

Workarounds

If you cannot upgrade immediately, either:

  • Config/code-level: wrap your getToken() calls so a thrown error is treated as "no token", e.g.

    let token = null
    try {
      token = await getToken({ req, secret })
    } catch {
      token = null
    }
  • Or strip/normalize the incoming Authorization header at the edge (proxy, middleware) before it reaches getToken(), rejecting values whose Bearer portion is not valid percent-encoding.

Credit

Reported by @​deprrous. Thank you for the responsible disclosure.

Severity

  • CVSS Score: 7.5 / 10 (High)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

nextauthjs/next-auth (@​auth/core)

v0.41.3

Compare Source

Bugfixes

  • core: getToken() now returns null instead of throwing when the Authorization header contains a malformed Bearer value
  • core: OAuth state, nonce, and PKCE check cookies are now bound to the provider that created them and are rejected when a different provider handles the callback
  • core: email addresses are Unicode-normalized (NFKC) before validation in the default email normalizer, closing a homoglyph @ bypass

Other

  • deps: resolve Dependabot alerts via cross-major dependency upgrades (#​13449)
  • deps: resolve Dependabot security advisories via pnpm overrides (#​13441)
  • deps: allow nodemailer 8 in peer dependency ranges (#​13434)
  • CI formatting and proxy deploy repairs (#​13444)

v0.41.2

Compare Source

Bugfixes

  • providers: add issuer to GitHub provider for RFC 9207 compliance (#​13410)

Other

  • sync package versions with npm registry (#​13414)

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the dependencies Pull requests that update a dependency file label Oct 3, 2026
@renovate

renovate Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor Author

⚠️ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: pnpm-lock.yaml

<--- Last few GCs --->

[1362:0xa147000]   414773 ms: Scavenge 1363.2 (1394.6) -> 1350.6 (1394.3) MB, pooled: 0 MB, 2.91 / 0.00 ms  (average mu = 0.324, current mu = 0.283) task; 
[1362:0xa147000]   416380 ms: Mark-Compact (reduce) 1405.3 (1434.3) -> 1313.0 (1339.8) MB, pooled: 0 MB, 136.35 / 0.01 ms  (+ 1367.0 ms in 100 steps since start of marking, biggest step 23.7 ms, walltime since start of marking 1535 ms) (average mu = 0.293
FATAL ERROR: Ineffective mark-compacts near heap limit Allocation failed - JavaScript heap out of memory
----- Native stack trace -----

 1: 0xf49c57 node::OOMErrorHandler(char const*, v8::OOMDetails const&) [/opt/containerbase/tools/node/24.8.0/bin/node]
 2: 0x13a6050 v8::Utils::ReportOOMFailure(v8::internal::Isolate*, char const*, v8::OOMDetails const&) [/opt/containerbase/tools/node/24.8.0/bin/node]
 3: 0x13a613f v8::internal::V8::FatalProcessOutOfMemory(v8::internal::Isolate*, char const*, v8::OOMDetails const&) [/opt/containerbase/tools/node/24.8.0/bin/node]
 4: 0x163ec25  [/opt/containerbase/tools/node/24.8.0/bin/node]
 5: 0x163ec52  [/opt/containerbase/tools/node/24.8.0/bin/node]
 6: 0x163ef4a v8::internal::Heap::RecomputeLimits(v8::internal::GarbageCollector, v8::base::TimeTicks) [/opt/containerbase/tools/node/24.8.0/bin/node]
 7: 0x164f46a  [/opt/containerbase/tools/node/24.8.0/bin/node]
 8: 0x1653810  [/opt/containerbase/tools/node/24.8.0/bin/node]
 9: 0x20e6641  [/opt/containerbase/tools/node/24.8.0/bin/node]
/usr/local/bin/node: line 18:  1362 Aborted                 /opt/containerbase/tools/node/24.8.0/bin/node "$@"

@changeset-bot

changeset-bot Bot commented Oct 3, 2026 •

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: b85807b

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@coderabbitai

coderabbitai Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Repository: TanStack/router/.coderabbit.yaml
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 9c4729ee-65d8-4fd5-933b-d8b39f32936d

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@nx-cloud

nx-cloud Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

View your CI Pipeline Execution ↗ for commit b85807b

Command Status Duration Result
nx run-many --target=build --exclude=examples/*... ✅ Succeeded 2m 14s View ↗
nx affected --targets=test:eslint,test:unit,tes... ✅ Succeeded <1s View ↗

☁️ Nx Cloud last updated this comment at 2026-10-03 23:18:43 UTC

@github-actions

github-actions Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

🚀 Changeset Version Preview

3 package(s) bumped directly, 10 bumped as dependents.

🟩 Patch bumps

Package Version Reason
@tanstack/react-router 1.170.41 → 1.170.42 Changeset
@tanstack/solid-router 1.170.38 → 1.170.39 Changeset
@tanstack/vue-router 1.170.37 → 1.170.38 Changeset
@tanstack/react-start 1.168.60 → 1.168.61 Dependent
@tanstack/react-start-client 1.168.39 → 1.168.40 Dependent
@tanstack/react-start-rsc 0.1.59 → 0.1.60 Dependent
@tanstack/react-start-server 1.167.46 → 1.167.47 Dependent
@tanstack/solid-start 1.168.57 → 1.168.58 Dependent
@tanstack/solid-start-client 1.168.37 → 1.168.38 Dependent
@tanstack/solid-start-server 1.167.44 → 1.167.45 Dependent
@tanstack/vue-start 1.168.56 → 1.168.57 Dependent
@tanstack/vue-start-client 1.167.40 → 1.167.41 Dependent
@tanstack/vue-start-server 1.167.44 → 1.167.45 Dependent

@pkg-pr-new

pkg-pr-new Bot commented Oct 3, 2026

Copy link
Copy Markdown
More templates

@tanstack/arktype-adapter

npm i https://pkg.pr.new/@tanstack/arktype-adapter@8595

@tanstack/eslint-plugin-router

npm i https://pkg.pr.new/@tanstack/eslint-plugin-router@8595

@tanstack/eslint-plugin-start

npm i https://pkg.pr.new/@tanstack/eslint-plugin-start@8595

@tanstack/history

npm i https://pkg.pr.new/@tanstack/history@8595

@tanstack/nitro-v2-vite-plugin

npm i https://pkg.pr.new/@tanstack/nitro-v2-vite-plugin@8595

@tanstack/react-router

npm i https://pkg.pr.new/@tanstack/react-router@8595

@tanstack/react-router-devtools

npm i https://pkg.pr.new/@tanstack/react-router-devtools@8595

@tanstack/react-router-ssr-query

npm i https://pkg.pr.new/@tanstack/react-router-ssr-query@8595

@tanstack/react-start

npm i https://pkg.pr.new/@tanstack/react-start@8595

@tanstack/react-start-client

npm i https://pkg.pr.new/@tanstack/react-start-client@8595

@tanstack/react-start-rsc

npm i https://pkg.pr.new/@tanstack/react-start-rsc@8595

@tanstack/react-start-server

npm i https://pkg.pr.new/@tanstack/react-start-server@8595

@tanstack/router-cli

npm i https://pkg.pr.new/@tanstack/router-cli@8595

@tanstack/router-core

npm i https://pkg.pr.new/@tanstack/router-core@8595

@tanstack/router-devtools

npm i https://pkg.pr.new/@tanstack/router-devtools@8595

@tanstack/router-devtools-core

npm i https://pkg.pr.new/@tanstack/router-devtools-core@8595

@tanstack/router-generator

npm i https://pkg.pr.new/@tanstack/router-generator@8595

@tanstack/router-plugin

npm i https://pkg.pr.new/@tanstack/router-plugin@8595

@tanstack/router-ssr-query-core

npm i https://pkg.pr.new/@tanstack/router-ssr-query-core@8595

@tanstack/router-utils

npm i https://pkg.pr.new/@tanstack/router-utils@8595

@tanstack/router-vite-plugin

npm i https://pkg.pr.new/@tanstack/router-vite-plugin@8595

@tanstack/solid-router

npm i https://pkg.pr.new/@tanstack/solid-router@8595

@tanstack/solid-router-devtools

npm i https://pkg.pr.new/@tanstack/solid-router-devtools@8595

@tanstack/solid-router-ssr-query

npm i https://pkg.pr.new/@tanstack/solid-router-ssr-query@8595

@tanstack/solid-start

npm i https://pkg.pr.new/@tanstack/solid-start@8595

@tanstack/solid-start-client

npm i https://pkg.pr.new/@tanstack/solid-start-client@8595

@tanstack/solid-start-server

npm i https://pkg.pr.new/@tanstack/solid-start-server@8595

@tanstack/start-client-core

npm i https://pkg.pr.new/@tanstack/start-client-core@8595

@tanstack/start-fn-stubs

npm i https://pkg.pr.new/@tanstack/start-fn-stubs@8595

@tanstack/start-plugin-core

npm i https://pkg.pr.new/@tanstack/start-plugin-core@8595

@tanstack/start-server-core

npm i https://pkg.pr.new/@tanstack/start-server-core@8595

@tanstack/start-static-server-functions

npm i https://pkg.pr.new/@tanstack/start-static-server-functions@8595

@tanstack/start-storage-context

npm i https://pkg.pr.new/@tanstack/start-storage-context@8595

@tanstack/valibot-adapter

npm i https://pkg.pr.new/@tanstack/valibot-adapter@8595

@tanstack/virtual-file-routes

npm i https://pkg.pr.new/@tanstack/virtual-file-routes@8595

@tanstack/vue-router

npm i https://pkg.pr.new/@tanstack/vue-router@8595

@tanstack/vue-router-devtools

npm i https://pkg.pr.new/@tanstack/vue-router-devtools@8595

@tanstack/vue-router-ssr-query

npm i https://pkg.pr.new/@tanstack/vue-router-ssr-query@8595

@tanstack/vue-start

npm i https://pkg.pr.new/@tanstack/vue-start@8595

@tanstack/vue-start-client

npm i https://pkg.pr.new/@tanstack/vue-start-client@8595

@tanstack/vue-start-server

npm i https://pkg.pr.new/@tanstack/vue-start-server@8595

@tanstack/zod-adapter

npm i https://pkg.pr.new/@tanstack/zod-adapter@8595

commit: b85807b

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants