CVE-2026-84685 PUBLISHED

Improper Cache Isolation in auth0/react-native-auth0 SDK Web Platform Credential Management

Assigner: Okta
Reserved: 01.09.2026 Published: 08.09.2026 Updated: 08.09.2026

The react-native-auth0 SDK's web platform implementation does not scope its in-memory token cache to individual user sessions when operating in a server-side rendering (SSR) environment where module state persists across HTTP requests. Under the listed preconditions, tokens cached in module memory can be retrieved across subsequent requests processed by the same server runtime.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N
CVSS Score: 6.5

Product Status

Vendor Auth0
Product react-native-auth0
Versions Default: unaffected
  • affected from 5.0.0 to 5.11.1 (excl.)

Solutions

Upgrade auth0/react-native-auth0 to version 5.11.1 or greater.

References

Problem Types

  • Exposure of Data Element to Wrong Session