Please do not report security vulnerabilities through public GitHub issues, pull requests, or discussions.
If you believe you have found a security vulnerability in this SDK, report it through Auth0's Responsible Disclosure Program. That page details the disclosure procedure, what is in scope, and what to expect after you submit a report.
Please include as much of the following as you can, so we can reproduce and assess the issue quickly:
- The affected module(s) and SDK version.
- Which platform(s) are affected (Android, iOS, or both).
- Steps to reproduce, ideally against one of the sample apps.
- The impact you believe the issue has.
Security fixes are released against the latest published version of the SDK. We recommend always depending on the most recent release; see the CHANGELOG for what is current.
Pre-release versions (-beta, -rc) are not covered by long-term support — fixes
land in the next pre-release or in the next stable version rather than being
backported.