Junglewise Threat Intelligence

CVE-2025-71399: Better Auth relies on better-call, which uses the rou3 router library. In affected versions of rou3, paths are normalized by removing empty

CVE-2025-71399 · Severity: high · CVSS 8.6 · Published 2026-08-02

Technologies: better-auth (npm). Vendors: npm, Better-Auth.

Executive brief

Better Auth is a comprehensive authentication framework used to manage user login and identity flows. An issue in its underlying router allows attackers to bypass security controls by using double-slash URLs (e.g., //sign-in/email instead of /sign-in/email), potentially circumventing disabled path restrictions and rate-limiting protections that are meant to prevent abuse.

Technical details

The vulnerability exists in the rou3 router library, which Better Auth uses via the better-call dependency. The affected versions of rou3 normalize URL paths by removing empty segments, causing /path, //path, and ///path to resolve to identical routes. If the network infrastructure does not normalize multiple slashes before reaching Better Auth (e.g., in environments without Vercel/Next.js or Cloudflare URL normalization enabled), an attacker can craft requests with double-slash paths to bypass path-based disabledPaths configuration and rate-limiting controls. The attack requires no authentication and can be exploited remotely over the network. The fix was introduced in rou3 after version 0.5.1; Better Auth v1.4.5 and later include the patched dependency.

Affected products

  • Better Auth Better Auth < 1.4.5

Timeline

  • 2025-12-16: disclosed
  • 2025-12-16: patched: Better Auth v1.4.5 or later includes patched rou3

References

Related threats