- EPSS 0.21%
- Veröffentlicht 01.08.2026 12:22:16
- Zuletzt bearbeitet 03.08.2026 20:16:41
better-auth versions greater than 1.3.34 and before 1.4.0 contain a vulnerability in the multi-session plugin's /sign-out after-hook, which trusts raw multi-session cookies and forwards extracted values to internalAdapter.deleteSessions without verif...
CVE-2026-53517
- EPSS 0.24%
- Veröffentlicht 15.07.2026 17:33:38
- Zuletzt bearbeitet 21.07.2026 16:00:22
Better Auth is an authentication and authorization library for TypeScript. From 1.4.8-beta.7 until 1.6.11, the @better-auth/oauth-provider POST /oauth2/token endpoint on the refresh_token grant performs a non-atomic read, validate, revoke, and mint s...
CVE-2026-45337
- EPSS 0.14%
- Veröffentlicht 15.07.2026 17:31:44
- Zuletzt bearbeitet 21.07.2026 04:21:25
Better Auth is an authentication and authorization library for TypeScript. From 1.6.0 until 1.6.11, the deviceAuthorization plugin treats any authenticated session as the owner of any pending device code because GET /device does not claim the row and...
CVE-2026-53514
- EPSS 0.14%
- Veröffentlicht 15.07.2026 17:30:46
- Zuletzt bearbeitet 21.07.2026 13:41:03
Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, and in 1.6.14 and later when invitation IDs can be obtained outside the invited mailbox and requireEmailVerificationOnInvitation: true is not enabled, the org...
CVE-2026-53515
- EPSS 0.24%
- Veröffentlicht 15.07.2026 17:27:00
- Zuletzt bearbeitet 21.07.2026 15:38:36
Better Auth is an authentication and authorization library for TypeScript. From 1.2.10 until 1.6.11, the @better-auth/sso plugin's POST /sso/register endpoint lets any organization member attach a new SSO provider to that organization because registe...
CVE-2026-53512
- EPSS 0.21%
- Veröffentlicht 15.07.2026 17:18:09
- Zuletzt bearbeitet 21.07.2026 13:33:47
Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, the legacy oidcProvider and mcp plugins expose OAuth token endpoints whose refresh_token grant authenticates only possession of the bound refreshToken row and...
CVE-2026-53518
- EPSS 0.23%
- Veröffentlicht 15.07.2026 17:17:06
- Zuletzt bearbeitet 21.07.2026 16:03:12
Better Auth is an authentication and authorization library for TypeScript. From 1.6.0 until 1.6.11, the @better-auth/oauth-provider POST /oauth2/token endpoint for the authorization_code grant redeems a single-use authorization code through a non-ato...
CVE-2026-53513
- EPSS 0.19%
- Veröffentlicht 15.07.2026 17:15:59
- Zuletzt bearbeitet 21.07.2026 15:39:52
Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, the @better-auth/sso plugin's POST /sso/register and POST /sso/update-provider endpoints accept attacker-controlled oidcConfig.userInfoEndpoint, tokenEndpoint...
CVE-2026-53516
- EPSS 0.15%
- Veröffentlicht 15.07.2026 17:13:16
- Zuletzt bearbeitet 21.07.2026 14:14:22
Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, Better Auth's OAuth callback auto-link gate in handleOAuthUserInfo accepts implicit account linking when the OAuth provider asserts email_verified: true witho...
CVE-2026-45364
- EPSS 0.3%
- Veröffentlicht 28.05.2026 21:34:51
- Zuletzt bearbeitet 21.07.2026 10:10:00
Better Auth is an authentication and authorization library for TypeScript. Prior to 1.4.17 and 1.5.0-beta.9, Better Auth's HTTP rate limiter keyed each request by the exact textual IP address it received in x-forwarded-for (or the configured IP-beari...