Mohi@disismohiPatch
A warning that the better-auth library <1.6.11 contains a critical CVE-2026-67336 (CVSS 8.7), with a fix expected next Monday.
Mohi@disismohiGeneral
The message notes that CVE‑2026‑67336 allows attack via insecure default support of the "none" algorithm, but provides no further technical or actionable details.
Infoflowcloud@infoflowcloudDisclosure
The tweet announces CVE‑2026‑67336, outlining insecure crypto defaults in certain plugins, but provides no PoC, exploit code, or patch details.
CVE@CVEnewDisclosure
The announcement highlights insecure cryptographic defaults in better-auth prior to 1.6.11—advertising the 'none' algorithm and accepting plain PKCE—but provides no PoC, exploit, or mitigation information.