CVE-2026-45364Patch

LOWCVSS 7.3 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Better Auth is an authentication and authorization library for TypeScript. Prior to 1.4.17 and 1.5.0-beta.9, Better Auth's HTTP rate limiter keyed each request by the exact textual IP address it received in x-forwarded-for (or the configured IP-bearing header). IPv6 clients controlling a typical /64 allocation could rotate through 2^64 distinct source addresses without exhausting the per-address counter, defeating rate limiting on /sign-in/email, /sign-up/email, /forget-password, and every other path the limiter protects. The same bug allowed a single client to vary the textual encoding of one IPv6 address (uppercase, compression, IPv4-mapped, hex-encoded IPv4-in-IPv6) and produce multiple distinct keys. This vulnerability is fixed in 1.4.17 and 1.5.0-beta.9.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-307

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Patch: 1 classified signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-05-19: 1Technical Details · 2026-05-19: 105-19
Signal classification1 categories
Patch
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • CCB Alert@CCBalert
    Patch

    Warning: #CVE-2026-45364 in Better Auth allows IPv6 clients to #bypass its rate limiting entirely, enabling unlimited #brute-force attacks on login and password reset. CVSS 7.3. https://github.com/advisories/GHSA-p6v2-xcpg-h6xw #Patch #Patch #Patch

    Post summary

    The advisory highlights that CVE‑2026‑45364 in Better Auth permits IPv6 clients to circumvent rate limiting, enabling brute‑force login and reset attacks, with a CVSS score of 7.3; it indicates a patch is available via the linked advisory.

    00000206
    7.2K followersView on X

Explore more