CVE-2026-84685: Improper Cache Isolation in auth0/react-native-auth0 SDK Web Platform Credential Management

Published Sep 8, 2026
·
Updated

The react-native-auth0 SDK's web platform implementation does not scope its in-memory token cache to individual user sessions when operating in a server-side rendering (SSR) environment where module state persists across HTTP requests. Under the listed preconditions, tokens cached in module memory can be retrieved across subsequent requests processed by the same server runtime.

Affected Software

1 affected component
auth0/react-native-auth0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade auth0/react-native-auth0 to a version that resolves this vulnerability.

    Fixed in 5.11.1

Event History

Sep 8, 2026
CVE Published
via MITRE·08:18 PM
Data Sourced
via MITRE·08:18 PM
RemedyDescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to cross-request token retrieval?

Deployments using the SDK's web platform implementation in a server-side rendering environment are exposed when module state persists across HTTP requests. In that condition, the in-memory token cache is not isolated to individual user sessions.

2

How can I determine whether my application is affected?

Check whether the application uses auth0/react-native-auth0 on the web in an SSR runtime that reuses the same server process or module state for subsequent requests. If tokens are cached in module memory under those conditions, tokens may be retrievable by later requests handled by that runtime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203