22 Total advisories
22 Vulnerabilities
0 Malware
Vulnerabilities
UNKNOWN
CVE-2025-71401
Better Auth affected by external request basePath modification DoS
HIGH 8.6
CVE-2025-71399
Better Auth's rou3 Dependency has Double-Slash Path Normalization which can Bypass disabledPaths Config and Rate Limits
UNKNOWN
CVE-2026-67337
Better Auth Has Two-Factor Authentication Bypass via Premature Session Caching (session.cookieCache)
LOW 3.8
CVE-2026-67334
Better Auth: Stale sessions persist after user deletion across admin, anonymous, and SCIM flows
UNKNOWN
CVE-2025-71404
Better Auth URL parameter HTML Injection (Reflected Cross-Site scripting)
HIGH 8.7
CVE-2026-67336
Better Auth has insecure cryptographic defaults in oidcProvider: alg=none advertised and plain PKCE accepted by default
HIGH 7.7
CVE-2026-67333
Better Auth has stored XSS in the auth-server origin via javascript: redirect_uri in oidc-provider and mcp
HIGH 8.3
CVE-2026-67327
Better Auth: Account takeover via pre-account hijacking on magic-link and email-OTP sign-in
HIGH 7.1
CVE-2025-71403
Better Auth allows bypassing the trustedOrigins Protection which leads to ATO
UNKNOWN
CVE-2025-71402
Better Auth's multi-session sign-out hook allows forged cookies to revoke arbitrary sessions
MEDIUM 5.3
CVE-2026-67335
Better Auth: OAuth callback accepts mismatched `state` when cookie-backed state storage is used without PKCE
HIGH 8.1
CVE-2026-53518
@better-auth/oauth-provider's OAuth authorization-code grant allows concurrent redemption when two token requests race the find-then-delete primitive
CRITICAL 9.1
CVE-2026-53512
Better Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp plugins
HIGH 8.1
CVE-2026-53517
Better Auth: OAuth refresh-token rotation forks the token family on concurrent redemption
HIGH 8.3
CVE-2026-53516
Better Auth has an account takeover issue via OAuth auto-link to unverified pre-registered email
HIGH 7.7
CVE-2026-53514
Better Auth vulnerable to unauthorized invitation acceptance via unverified email match in organization plugin
HIGH 7.6
CVE-2026-45337
Better Auth: Device authorization approve and deny accept any authenticated session while the user code is pending
HIGH 7.3
CVE-2026-45364
Better Auth: Rate limiter keys IPv6 addresses individually and is bypassable via prefix rotation
UNKNOWN
CVE-2024-56734
Better Auth has an Open Redirect Vulnerability in Verify Email Endpoint
UNKNOWN
CVE-2025-27143
Beter Auth has an Open Redirect via Scheme-Less Callback Parameter
HIGH 8.6
CVE-2025-61928
Better Auth: Unauthenticated API key creation through api-key plugin
UNKNOWN
CVE-2025-53535
Better Auth Open Redirect Vulnerability in originCheck Middleware Affects Multiple Routes
Ready to move
Start Securing
Free, no credit card | First findings in minutes