-
-
Notifications
You must be signed in to change notification settings - Fork 3.9k
Closed
Labels
bugSomething isn't workingSomething isn't workinginvalid reproductionThe issue did not have a detectable valid reproduction URLThe issue did not have a detectable valid reproduction URLtriageUnseen or unconfirmed by a maintainer yet. Provide extra information in the meantime.Unseen or unconfirmed by a maintainer yet. Provide extra information in the meantime.
Description
Environment
System:
OS: macOS 15.5
CPU: (14) arm64 Apple M3 Max
Memory: 82.19 MB / 36.00 GB
Shell: 5.9 - /bin/zsh
Binaries:
Node: 22.5.1 - /opt/homebrew/bin/node
Yarn: 1.22.22 - ~/.npm_packages/bin/yarn
npm: 10.8.2 - /opt/homebrew/bin/npm
Browsers:
Chrome: 138.0.7204.184
Safari: 18.5
npmPackages:
next: 15.4.4 => 15.2.3
next-auth: ^4.24.11 => 4.24.11
react: ^18.3.1 => 18.3.1```
### Reproduction URL
no-url.com
### Describe the issue
CVE Details
Published: Aug 1, 2025
The jose versions through 6.0.10 was discovered to contain weak encryption.
[Reference](https://github.com/advisories/GHSA-m523-xm42-q7ff)
### How to reproduce
npm install next-auth then scan with checkmarkx
### Expected behavior
scan result without issues
Metadata
Metadata
Assignees
Labels
bugSomething isn't workingSomething isn't workinginvalid reproductionThe issue did not have a detectable valid reproduction URLThe issue did not have a detectable valid reproduction URLtriageUnseen or unconfirmed by a maintainer yet. Provide extra information in the meantime.Unseen or unconfirmed by a maintainer yet. Provide extra information in the meantime.