File: security.md | Updated: 11/15/2025
š NextAuth.js is now part of Better Auth !
Version: v4
On this page
Reporting a Vulnerabilityā
NextAuth.js practices responsible disclosure.
We request that you contact us directly to report serious issues that might impact the security of sites using NextAuth.js.
If you contact us regarding a serious issue:
The best way to report an issue is by contacting us via email at info@balazsorban.com , hi@thvu.dev and yo@ndo.dev or raise a public issue requesting someone get in touch with you via whatever means you prefer for more details. (Please do not disclose sensitive details publicly at this stage.)
note
For less serious issues (e.g. RFC compliance for unsupported flows or potential issues that may cause a problem in the future) it is appropriate to submit these these publically as bug reports or feature requests or to raise a question to open a discussion around them.
Supported Versionsā
Security updates are only released for the current version.
Old releases are not maintained and do not receive updates.