Tag
medium
advisory
Better Auth Rate Limiter Bypass via IPv6 Prefix Rotation (CVE-2026-45364)
2 rulesBetter Auth versions before 1.4.17 and pre-release versions before 1.5.0-beta.9 are vulnerable to CVE-2026-45364, a rate-limiting bypass that allows IPv6 clients to rotate through numerous source addresses or vary the textual encoding of one IPv6 address, effectively defeating rate limiting on authentication endpoints, potentially leading to credential stuffing, account enumeration, and amplification of password-reset email fan-out.
better-auth +4
rate-limiting
authentication
ipv6
cve-2026-45364
2r
critical
advisory
OpenClaw Webhook Rate Limit Bypass Vulnerability (CVE-2026-34505)
2 rules 1 TTP 1 CVEOpenClaw before 2026.3.12 applies rate limiting only after successful webhook authentication, allowing attackers to bypass rate limits and brute-force webhook secrets leading to forged webhook submission.
rate-limiting
brute-force
webhook
cve-2026-34505
2r
1t
1c