8.1
CVE-2026-53517
- EPSS 0.24%
- Veröffentlicht 15.07.2026 17:33:38
- Zuletzt bearbeitet 21.07.2026 16:00:22
- CVE-Watchlists
- Unerledigt
Better Auth OAuth Provider: Refresh Token Rotation Race Condition Allows Concurrent Replay and Token Family Forking
Better Auth is an authentication and authorization library for TypeScript. From 1.4.8-beta.7 until 1.6.11, the @better-auth/oauth-provider POST /oauth2/token endpoint on the refresh_token grant performs a non-atomic read, validate, revoke, and mint sequence on the oauthRefreshToken row, allowing concurrent requests with the same parent refresh token to pass the revoked check and create forked refresh-token families; the vulnerable range also includes embedded better-auth plugin versions before 1.6.0. This issue is fixed in version 1.6.11.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Better-auth ≫ Better-auth/oauth-provider SwPlatformnode.js Version >= 1.6.0 < 1.6.11
Better-auth ≫ Better Auth SwPlatformnode.js Version >= 1.4.9 < 1.6.11
Better-auth ≫ Better Auth Version1.4.8 Update- SwPlatformnode.js
Better-auth ≫ Better Auth Version1.4.8 Updatebeta7 SwPlatformnode.js
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.24% | 0.152 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 8.1 | 2.8 | 5.2 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
|
CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.
CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition
The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check.
https://github.com/better-auth/better-auth/releases/tag/v1.6.11
https://github.com/better-auth/better-auth/security/advisories/GHSA-392p-2q2v-4372
https://github.com/better-auth/better-auth/commit/c6918ecc9e3a75892169415d7f6c95b591b6a52d