CVE-2026-53517
- EPSS 0.24%
- Veröffentlicht 15.07.2026 17:33:38
- Zuletzt bearbeitet 21.07.2026 16:00:22
Better Auth is an authentication and authorization library for TypeScript. From 1.4.8-beta.7 until 1.6.11, the @better-auth/oauth-provider POST /oauth2/token endpoint on the refresh_token grant performs a non-atomic read, validate, revoke, and mint s...
CVE-2026-53518
- EPSS 0.23%
- Veröffentlicht 15.07.2026 17:17:06
- Zuletzt bearbeitet 21.07.2026 16:03:12
Better Auth is an authentication and authorization library for TypeScript. From 1.6.0 until 1.6.11, the @better-auth/oauth-provider POST /oauth2/token endpoint for the authorization_code grant redeems a single-use authorization code through a non-ato...
CVE-2026-41427
- EPSS 0.21%
- Veröffentlicht 24.04.2026 19:23:20
- Zuletzt bearbeitet 13.05.2026 19:36:38
Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.5, the clientPrivileges option documents a create action, but the OAuth client creation endpoints did not invoke the hook before persisting new clients. Deploymen...