---
cve: "CVE-2026-73419"
severity: "MEDIUM"
cvss: 6.8
epss: "0.2%"
vendor: "nextauthjs"
kev: false
exploited: false
published: "2026-08-12 20:23:39"
tags: [cve, security, medium]
source: tsecurity.de CVE-Dossier
exported: "2026-09-21T14:48:04+02:00"
---

# CVE-2026-73419

> 6.8 MEDIUM · 🧪 PoC

## Beschreibung

NextAuth.js provides authentication for Next.js. Prior to@auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, Auth.js stores the OAuth/OIDC anti-CSRF checks state, nonce, and the PKCE verifier in global cookies that are not bound to the provider that created them. On callback, a check value minted during a sign-in started with one provider can satisfy the callback for a different provider because the stored cookie is not verified against the callback provider's identity, including the provider ID, issuer, client ID, or redirect URI. In a multi-provider application that permits account linking while logged in, when one provider's authorization request is observable and a target provider callback can be satisfied without a PKCE verifier, an attacker can lure a victim into starting a legitimate same-origin flow and link the attacker's target-provider account to the victim's Auth.js user. The linked provider grants the attacker persistent sign-in to the victim's account, while cross-site request forgery alone is insufficient. This issue is fixed in @auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Hoch | good |
| PR Privilegien | Keine | bad |
| UI Interaktion | Erforderlich | good |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Keine | good |

## Patch verfügbar (OSV)

- d857eec560fb99c8b18d3b22a2693b849a62d1c3 (Commit)
- 5af7357fb40c82e0c66f940319321260ddfd44dc (Commit)

## Referenzen

- <https://github.com/nextauthjs/next-auth/security/advisories/GHSA-x445-f3h2-j279>
- <https://github.com/nextauthjs/next-auth/pull/13469>
- <https://github.com/nextauthjs/next-auth/commit/5bca2399a79ba8d116ca5179b4b1ebcd152e7f05>
- <https://github.com/nextauthjs/next-auth/commit/9f7a97fade9b1319bb9ac19fc9828d62e0a2a852>
- <https://github.com/nextauthjs/next-auth/releases/tag/@auth/core@0.41.3>
- <https://github.com/nextauthjs/next-auth/releases/tag/next-auth@4.24.15>
- <https://github.com/nextauthjs/next-auth/releases/tag/next-auth@5.0.0-beta.32>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-73419) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
