A critical vulnerability tracked as CVE-2026-73421 and GHSA-8fpg-xm3f-6cx3 affects NextAuth.js / next-auth in the v5 beta series before 5.0.0-beta.32, allowing authentication checks to fail open under server misconfiguration. When provider settings were invalid—such as missing issuer or authorization endpoints, or an unset AUTH_SECRET—@auth/core could return an HTTP 500 response containing a JSON error object, and NextAuth wrappers incorrectly treated that body as session data instead of rejecting it.
Because the returned error object was truthy, common authorization patterns such as checking whether auth or req.auth existed could mistakenly grant access to unauthenticated requests and expose protected routes. The maintainers fixed the issue in next-auth@5.0.0-beta.32 by making non-OK session responses return null so auth() fails closed, and the release also pulled in related security hardening from @auth/core@0.41.3, including fixes for malformed Bearer token handling, provider-bound OAuth check cookies, and NFKC email normalization.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
GitHub security advisories published CVE-2026-73421 for NextAuth.js / next-auth, describing a critical authentication bypass caused by existence-based auth checks failing open under server misconfiguration. The advisory rated the issue Critical with a CVSS 4.0 base score of 9.1 and identified 5.0.0-beta.32 as the fixed version.
The next-auth project released version 5.0.0-beta.32, incorporating the fix for the fail-open authentication issue along with other security updates from @auth/core@0.41.3. The release changed non-OK session handling so checks such as !!auth no longer grant access on configuration errors.
A next-auth commit fixed a flaw where invalid provider configuration could cause auth() wrappers to treat an error object as a valid session, potentially exposing protected routes. The change introduced logic to return null on non-OK session responses and added regression tests to ensure auth() entry points fail closed.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.