Description
Auth0-PHP is a PHP SDK for Auth0 Authentication and Management APIs. In applications built with the Auth0-PHP SDK, the audience validation in access tokens is performed improperly. Without proper validation, affected applications may accept ID tokens as Access tokens. Projects are affected if they use Auth0-PHP SDK versions between v8.0.0 and v8.17.0, or applications using the following SDKs that rely on the Auth0-PHP SDK versions between v8.0.0 and v8.17.0: Auth0/symfony versions between 5.0.0 and 5.5.0, Auth0/laravel-auth0 versions between 7.0.0 and 7.19.0, and/or Auth0/wordpress plugin versions between 5.0.0-BETA0 and 5.4.0. Auth0/Auth0-PHP version 8.18.0 contains a patch for the issue.
Published: 2025-12-17
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-j2vm-wrq3-f7gf Auth0-PHP SDK has Improper Audience Validation
History

Thu, 05 Mar 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Auth0 laravel-auth0
Auth0 symfony
Auth0 wp-auth0
CPEs cpe:2.3:a:auth0:auth0-php:*:*:*:*:*:*:*:*
cpe:2.3:a:auth0:laravel-auth0:*:*:*:*:*:laravel:*:*
cpe:2.3:a:auth0:symfony:*:*:*:*:*:*:*:*
cpe:2.3:a:auth0:wp-auth0:*:*:*:*:*:wordpress:*:*
Vendors & Products Auth0 laravel-auth0
Auth0 symfony
Auth0 wp-auth0

Thu, 18 Dec 2025 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Auth0
Auth0 auth0-php
Vendors & Products Auth0
Auth0 auth0-php

Wed, 17 Dec 2025 22:15:00 +0000

Type Values Removed Values Added
Description Auth0-PHP is a PHP SDK for Auth0 Authentication and Management APIs. In applications built with the Auth0-PHP SDK, the audience validation in access tokens is performed improperly. Without proper validation, affected applications may accept ID tokens as Access tokens. Projects are affected if they use Auth0-PHP SDK versions between v8.0.0 and v8.17.0, or applications using the following SDKs that rely on the Auth0-PHP SDK versions between v8.0.0 and v8.17.0: Auth0/symfony versions between 5.0.0 and 5.5.0, Auth0/laravel-auth0 versions between 7.0.0 and 7.19.0, and/or Auth0/wordpress plugin versions between 5.0.0-BETA0 and 5.4.0. Auth0/Auth0-PHP version 8.18.0 contains a patch for the issue.
Title Auth0-PHP SDK has Improper Audience Validation
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Auth0 Auth0-php Laravel-auth0 Symfony Wp-auth0
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-12-18T15:07:22.780Z

Reserved: 2025-12-15T18:05:52.209Z

Link: CVE-2025-68129

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2025-12-17T22:16:01.713

Modified: 2026-03-05T19:43:11.997

Link: CVE-2025-68129

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-12-18T09:56:01Z

Weaknesses