next-auth@4.24.15

TimoBolkart/FLAME-Universenext-auth@4.24.15Jul 20, 2026by gustavovalverde

AI Summary

A security patch release for the 4.x line addressing vulnerabilities in token handling, OAuth cookie security, and email validation, while also restoring CommonJS compatibility.

Key Highlights

  • getToken() returns null instead of throwing for malformed Bearer tokens
  • OAuth cookies are now bound to the specific provider to prevent cross-provider attacks
  • Email addresses are Unicode-normalized to prevent homoglyph bypasses
  • Restored CommonJS compatibility by pinning uuid to ^11.1.1

Full Release Notes

Security patch release for the 4.x line.

- `getToken()` now returns `null` instead of throwing when the `Authorization` header contains a malformed Bearer value.
- OAuth `state`, `nonce`, and PKCE check cookies are now bound to the provider that created them and are rejected when a different provider handles the callback. Sign-ins in flight across the upgrade fail once and succeed on retry.
- Email addresses are Unicode-normalized (NFKC) before validation in the email sign-in flow, closing a homoglyph `@` bypass.
- An explicitly configured `NEXTAUTH_URL` now takes precedence over the auto-detected forwarded host in trusted-host mode.
- Restores CommonJS compatibility by pinning `uuid` to `^11.1.1`; the 14.x line is ESM-only and broke `require()` on Node versions below 20.19.