The AuthKit library for Next.js provides convenient helpers for authentication and session management using WorkOS & AuthKit with Next.js. In authkit-nextjs version 2.11.0 and below, authenticated responses do not defensively apply anti-caching headers. In environments where CDN caching is enabled, this can result in session tokens being included in cached responses and subsequently served to multiple users. Next.js applications deployed on Vercel are unaffected unless they manually enable CDN caching by setting cache headers on authenticated paths. Patched in authkit-nextjs 2.11.1, which applies anti-caching headers to all responses behind authentication.
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-p8pf-44ff-93gf authkit-nextjs may let session cookies be cached in CDNs
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 21 Nov 2025 01:45:00 +0000

Type Values Removed Values Added
Description The AuthKit library for Next.js provides convenient helpers for authentication and session management using WorkOS & AuthKit with Next.js. In authkit-nextjs version 2.11.0 and below, authenticated responses do not defensively apply anti-caching headers. In environments where CDN caching is enabled, this can result in session tokens being included in cached responses and subsequently served to multiple users. Next.js applications deployed on Vercel are unaffected unless they manually enable CDN caching by setting cache headers on authenticated paths. Patched in authkit-nextjs 2.11.1, which applies anti-caching headers to all responses behind authentication.
Title authkit-nextjs may let session cookies be cached in CDNs
Weaknesses CWE-524
References
Metrics cvssV4_0

{'score': 8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-11-21T01:29:22.606Z

Reserved: 2025-11-10T22:29:34.876Z

Link: CVE-2025-64762

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-11-21T02:15:44.077

Modified: 2025-11-21T02:15:44.077

Link: CVE-2025-64762

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.