Here is a list of Auth0 security bulletins that address security vulnerabilities in Auth0 software. Each bulletin contains a description of the vulnerability, how to identify if you are affected, and what to do to fix it.
DateBulletin numberTitleAffected software
December 21, 2022Auth0 BulletinAuth0 security bulletin for jsonwebtokennode-jsonwebtoken
December 12, 2022CVE-2022-23505Security Update for passport-wsfed-saml2 Librarypasspord-wsfed-saml2
March 30, 2022CVE-2022-24794Security Update for Express OpenID Connect Libraryexpress-openid-connect
December 16, 2021CVE-2021-43812Security Update for Next.js Auth0 Library <=1.6.1nextjs-auth0
December 08, 2021CVE-2021-41246Security Update for Express OpenID Connect >= 2.3.0, <= 2.5.1express-openid-connect
June 23, 2021CVE-2021-32702Security Update for Auth0 Next.js <= 1.4.1nextjs-auth0
June 4, 2021CVE-2021-32641Security Update for Auth0 Lock <= 11.30.0Auth0 Lock
November 05, 2020CVE-2020-15259Auth0 Security Bulletin for ad-ldap-connector versions <= 5.0.12AD/LDAP Connector
October 21, 2020CVE-2020-15240Security Update for omniauth-auth0 JWT Validationomniauth-auth0
August 16, 2020CVE-2020-15119Security Update for Auth0 Lock <= 11.25.1Auth0 Lock
July 28, 2020CVE-2020-15125Auth0 Security Bulletin for node-auth0 <= 2.27.0node-auth0
June 30, 2020CVE-2020-15084Auth0 Security Bulletin for express-jwt versions < 6.0.0express-jwt
April 09, 2020CVE-2020-5263Auth0 Security Bulletin for auth0.js versions <= 9.13.1Auth0.js
March 31, 2020Auth0 BulletinAuth0 Security Bulletin for WordPress Plugin for Auth0 versions < 4.0.0WordPress Plugin for Auth0
January 31, 2020CVE-2019-20173Auth0 Security Bulletin for WordPress Plugin for Auth0 versions 3.11.0, 3.11.1 and 3.11.2WordPress Plugin for Auth0
January 30, 2020CVE-2019-20174Auth0 Security Bulletin for Auth0 Lock < 11.21.0Auth0 Lock
October 04, 2019CVE-2019-16929Auth0 Security Bulletin for auth0.net between versions 5.8.0 and 6.5.3 inclusiveauth0.net
September 05, 2019Auth0 bulletinAuth0 Security Bulletin for assigning scopes based on email addressCustom code within Auth0 rules
July 23, 2019CVE-2019-13483Security Bulletin for Passport-SharePoint < 0.4.0Passport-SharePoint
February 15, 2019CVE-2019-7644Security Bulletin for Auth0-WCF-Service-JWT < 1.0.4Auth0-WCF-Service-JWT
January 10, 2019Auth0 bulletinAuth0 Security Bulletin for Vulnerable Patterns in Custom Rule CodeCustom code within Auth0 Rules
August 6, 2018CVE-2018-15121Security vulnerability in deprecated Auth0 middleware for ASP.NETauth0-aspnet, auth0-aspnet-owin
June 5, 2018CVE-2018-11537Security update for angular-jwt allowlist bypassangular-jwt
April 4, 2018CVE-2018-6874Security vulnerability for Auth0 authentication serviceAuth0 Authentication Service
April 4, 2018CVE 2018-6873Security vulnerability for Auth0 authentication serviceAuth0 Authentication Service
February 26, 2018CVE 2018-7307Security vulnerability for auth0.js < 9.3Auth0.js
December 22, 2017CVE 2017-16897Security update for passport-wsfed-saml2 Passport strategy librarypassport-wsfed-saml2 Passport strategy library
December 4, 2017CVE 2017-17068Security update for auth0.js popup callback vulnerabilityAuth0.js