Product
medium
advisory
Better Auth Path Normalization Vulnerability (CVE-2025-71399)
1 CVEBetter Auth versions prior to 1.4.5 contain a path normalization vulnerability in the rou3 library that allows attackers to bypass disabledPaths configurations and rate limits via URL path manipulation.
Better Auth
web-application
security-bypass
cve-2025-71399
1c
medium
advisory
Better Auth Rate Limiter Bypass via IPv6 Prefix Rotation (CVE-2026-45364)
2 rulesBetter Auth versions before 1.4.17 and pre-release versions before 1.5.0-beta.9 are vulnerable to CVE-2026-45364, a rate-limiting bypass that allows IPv6 clients to rotate through numerous source addresses or vary the textual encoding of one IPv6 address, effectively defeating rate limiting on authentication endpoints, potentially leading to credential stuffing, account enumeration, and amplification of password-reset email fan-out.
better-auth +4
rate-limiting
authentication
ipv6
cve-2026-45364
2r