Description
The react-native-auth0 SDK's web platform implementation does not scope its in-memory token cache to individual user sessions when operating in a server-side rendering (SSR) environment where module state persists across HTTP requests. Under the listed preconditions, tokens cached in module memory can be retrieved across subsequent requests processed by the same server runtime.
Published: 2026-09-08
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Token leakage across user sessions
Action: Apply Patch
AI Analysis

Impact

The Auth0 react-native-auth0 SDK's web platform implementation does not isolate its in‑memory token cache to individual user sessions when running in a server‑side rendering environment where module state persists across HTTP requests. This flaw means that access tokens stored in memory for one user can be retrieved by subsequent requests handled by the same server runtime, exposing sensitive credentials and permitting unauthorized access to protected resources. The vulnerability is classified as CWE‑488, reflecting improper separation of token data across sessions.

Affected Systems

Auth0 react-native-auth0 library versions earlier than 5.11.1 that use web platform credential management in a server‑side rendering configuration where module state is shared between requests are affected. Systems deploying these earlier versions in such an environment are at risk of token leakage.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity, and the EPSS score is not provided, so the likelihood of exploitation cannot be quantified. The vulnerability is not listed in CISA's KEV catalog. Based on the description, it is inferred that an attacker would need to target a server running the vulnerable SDK in an environment that shares module state across requests. If such conditions exist, an attacker could read tokens from memory and gain unauthorized access, making the risk moderate to high in heavily trafficked applications.

Generated by OpenCVE AI on September 9, 2026 at 10:22 UTC.

Remediation

Vendor Solution

Upgrade auth0/react-native-auth0 to version 5.11.1 or greater.


OpenCVE Recommended Actions

  • Upgrade the Auth0 react-native-auth0 SDK to version 5.11.1 or newer.
  • If the web platform credential management feature is not required, disable it in the SDK configuration.
  • Reconfigure the server‑side rendering environment to ensure module state does not persist across HTTP requests, such as by using isolated runtime contexts for each request.
  • As a temporary workaround, clear the in‑memory token cache after each user session or at the start of each request.
  • If the above measures cannot be applied immediately, monitor application logs for cross‑session token access and rotate tokens promptly if leakage is suspected.

Generated by OpenCVE AI on September 9, 2026 at 10:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Auth0
Auth0 react-native-auth0
Vendors & Products Auth0
Auth0 react-native-auth0

Thu, 10 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description The react-native-auth0 SDK's web platform implementation does not scope its in-memory token cache to individual user sessions when operating in a server-side rendering (SSR) environment where module state persists across HTTP requests. Under the listed preconditions, tokens cached in module memory can be retrieved across subsequent requests processed by the same server runtime.
Title Improper Cache Isolation in auth0/react-native-auth0 SDK Web Platform Credential Management
Weaknesses CWE-488
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N'}


Subscriptions

Auth0 React-native-auth0
cve-icon MITRE

Status: PUBLISHED

Assigner: Okta

Published:

Updated: 2026-09-10T14:44:48.261Z

Reserved: 2026-09-01T22:41:00.184Z

Link: CVE-2026-84685

cve-icon Vulnrichment

Updated: 2026-09-10T14:44:37.678Z

cve-icon NVD

Status : Deferred

Published: 2026-09-08T21:18:46.973

Modified: 2026-09-10T15:17:48.687

Link: CVE-2026-84685

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T20:06:36Z

Weaknesses
  • CWE-488

    Exposure of Data Element to Wrong Session