
Warning: #CVE-2026-45364 in Better Auth allows IPv6 clients to #bypass its rate limiting entirely, enabling unlimited #brute-force attacks on login and password reset. CVSS 7.3. https://github.com/advisories/GHSA-p6v2-xcpg-h6xw #Patch #Patch #Patch
Post summary
The advisory highlights that CVE‑2026‑45364 in Better Auth permits IPv6 clients to circumvent rate limiting, enabling brute‑force login and reset attacks, with a CVSS score of 7.3; it indicates a patch is available via the linked advisory.
