


Perceptive Security
SOC/SIEM Consultancy

Better Auth relies on better-call, which uses the rou3 router library. In affected versions of rou3, paths are normalized by removing empty segments, so /path, …
Published:
2 August 2026 at 00:00:00
Alert date:
2 August 2026 at 16:02:48
Source:
nvd.nist.gov
Web Technologies, Identity & Access, Supply Chain & Dependencies
CVE-2025-71399 affects Better Auth versions prior to 1.4.5, which relies on the rou3 router library through better-call. The vulnerability stems from rou3 normalizing URL paths by removing empty segments, causing /path, //path, and ///path to resolve to the same route. Attackers can exploit this behavior by submitting requests with extra slashes in the URL path to bypass disabledPaths configuration settings and circumvent path-based rate limiting controls. The fix was bundled in Better Auth version 1.4.5, which includes a patched version of rou3. Deployments that use a proxy or platform that normalizes URLs by collapsing multiple slashes are not affected. The issue represents an authentication and access control bypass risk in web applications using Better Auth.
Technical details
Mitigation steps:
Affected products:
Better Auth
rou3
better-call
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2025-71399
https://github.com/better-auth/better-auth/commit/f60b43fa648399534507c9ac7db36d705b8874c3
https://github.com/better-auth/better-auth/security/advisories/GHSA-x732-6j76-qmhm
https://www.vulncheck.com/advisories/better-auth-before-path-normalization-bypass-via-rou3
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
