@kinde-oss/kinde-auth-nextjs is vulnerable to Improper Certificate Validation
95
Critical Risk
Affected versions of the package allow login bypass due to a failure in validating the certificate during the authentication process. As a result, an attacker could exploit this vulnerability to bypass authentication and gain unauthorized access.
You are affected if you are using a version that falls within the vulnerable range.
@kinde-oss/kinde-auth-nextjs is vulnerable to Improper Certificate Validation in versions 1.8.3 - 2.3.11.
Upgrade the @kinde-oss/kinde-auth-nextjs library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant