next-auth@4.24.15
nextauthjs/next-authnext-auth@4.24.15Jul 20, 2026by gustavovalverde
AI Summary
This is a security and compatibility patch release that addresses critical vulnerabilities in authentication flows, improves OAuth state management, and restores CommonJS support for older Node.js versions.
Key Highlights
- Security patch: getToken() now returns null instead of throwing when the Authorization header contains a malformed Bearer value.
- OAuth cookies (state, nonce, PKCE) are now bound to the specific provider that created them to prevent cross-provider attacks.
- Email addresses are now Unicode-normalized (NFKC) before validation to prevent homoglyph bypass attacks.
- An explicitly configured NEXTAUTH_URL now takes precedence over the auto-detected forwarded host in trusted-host mode.
- Restores CommonJS compatibility by pinning the uuid package to version 11.x, as version 14.x is ESM-only.
Full Release Notes
Security patch release for the 4.x line. - `getToken()` now returns `null` instead of throwing when the `Authorization` header contains a malformed Bearer value. - OAuth `state`, `nonce`, and PKCE check cookies are now bound to the provider that created them and are rejected when a different provider handles the callback. Sign-ins in flight across the upgrade fail once and succeed on retry. - Email addresses are Unicode-normalized (NFKC) before validation in the email sign-in flow, closing a homoglyph `@` bypass. - An explicitly configured `NEXTAUTH_URL` now takes precedence over the auto-detected forwarded host in trusted-host mode. - Restores CommonJS compatibility by pinning `uuid` to `^11.1.1`; the 14.x line is ESM-only and broke `require()` on Node versions below 20.19.