top of page
perceptive_background_267k.jpg

Better Auth relies on better-call, which uses the rou3 router library. In affected versions of rou3, paths are normalized by removing empty segments, so /path, …

Published:

2 augustus 2026 om 00:00:00

Alert date:

2 augustus 2026 om 16:02:48

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Identity & Access, Supply Chain & Dependencies

CVE-2025-71399 affects Better Auth versions prior to 1.4.5, which relies on the rou3 router library through better-call. The vulnerability stems from rou3 normalizing URL paths by removing empty segments, causing /path, //path, and ///path to resolve to the same route. Attackers can exploit this behavior by submitting requests with extra slashes in the URL path to bypass disabledPaths configuration settings and circumvent path-based rate limiting controls. The fix was bundled in Better Auth version 1.4.5, which includes a patched version of rou3. Deployments that use a proxy or platform that normalizes URLs by collapsing multiple slashes are not affected. The issue represents an authentication and access control bypass risk in web applications using Better Auth.

Technical details

Mitigation steps:

Affected products:

Better Auth
rou3
better-call

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page