Overview In Auth0 Next.js SDK versions 4.0.1 to 4.6.0, __session cookies set by auth0.middleware may be cached by CDNs due to missing Cache-Control headers.
Am I Affected? You are affected by this vulnerability if you meet the following preconditions:
Fix Upgrade auth0/nextjs-auth0 to v4.6.1.
{ "github_reviewed": true, "cwe_ids": [ "CWE-525" ], "severity": "HIGH", "nvd_published_at": "2025-06-04T21:15:40Z", "github_reviewed_at": "2025-06-04T21:24:52Z" }