Junglewise Threat Intelligence

Auth.js incorrect behavior order in email normalizer allows account takeover

Severity: critical · CVSS 9.1 · Published 2026-07-23

Technologies: Auth.js NextAuth.js. Vendors: Auth.js.

Executive brief

Auth.js (formerly NextAuth.js) is a popular authentication library for web applications. A vulnerability in its email sign-in flow allows attackers to bypass security checks by using special characters that look like an '@' symbol. This can result in passwordless login links being sent to an attacker's email address instead of the intended user, leading to full account takeover without any interaction from the victim.

Technical details

The vulnerability is an instance of 'validate before canonicalize' (CWE-180) within the default email identifier normalizer. The library checks for a single '@' character before applying Unicode NFKC/NFKD normalization. An attacker can provide an email address containing a Unicode homoglyph that is not U+0040 but canonicalizes to it. While the Auth.js validator sees only one ASCII '@', downstream mail libraries that perform normalization will see two '@' separators, potentially misrouting the magic-link token to an attacker-controlled domain. This allows for unauthenticated account takeover if the application uses the default normalizer and a normalization-aware SMTP sender. Patches are available in @auth/core 0.41.3, next-auth 4.24.15, and 5.0.0-beta.32.

Affected products

  • Auth.js @auth/core >= 0.1.0, < 0.41.3
  • Auth.js next-auth >= 4.10.3, < 4.24.15; >= 5.0.0-beta.1, <= 5.0.0-beta.31

Timeline

  • 2026-07-20: patched: Initial patch release date for some versions
  • 2026-07-23: advisory: GitHub Advisory published

References

Related threats