Package impact
npm / better-auth
| CVE | Severity | CVSS | Risk | Flags | OS | Vendor | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-45364 | high | 7.3 | 7.3 | 14d ago | Better Auth is an authentication and authorization library for TypeScript. Prior to 1.4.17 and 1.5.0-beta.9, Better Auth's HTTP rate limiter keyed each request by the exact textual IP address it rece… | |||
| CVE-2025-61928 | unknown | — | — | 8mo ago | Better Auth: Unauthenticated API key creation through api-key plugin | |||
| CVE-2025-53535 | unknown | — | — | 11mo ago | Better Auth Open Redirect Vulnerability in originCheck Middleware Affects Multiple Routes | |||
| CVE-2025-27143 | unknown | — | — | 1y ago | Beter Auth has an Open Redirect via Scheme-Less Callback Parameter | |||
| CVE-2024-56734 | unknown | — | — | 1y ago | Better Auth has an Open Redirect Vulnerability in Verify Email Endpoint |