Executive brief
Better Auth is an authentication framework used to manage user login and identity services in web applications. When misconfigured without an explicit base URL setting, an attacker can send a specially crafted request as the first call to a server to poison the router's path configuration, causing the authentication service to return 404 errors for all subsequent requests. This results in a complete denial of service for all users trying to authenticate or use the affected application.
Technical details
The vulnerability exists in Better Auth's baseURL initialization logic, which falls back to extracting configuration from X-Forwarded-Host and X-Forwarded-Proto headers when the BETTER_AUTH_URL environment variable is not set. An attacker who sends the first request to the server after startup can craft these headers (e.g., X-Forwarded-Proto: "some:" and X-Forwarded-Host: "junk") to poison the router's basePath derivation. Once poisoned, the basePath remains corrupted until server restart, causing all routing to fail with 404 responses for legitimate requests. The attack requires no authentication and is network-reachable, but exploitability is limited to servers without explicit baseURL configuration and where the attacker can time the first request after startup. Patch is available in version 1.4.2.
Affected products
- better-auth better-auth < 1.4.2
Timeline
- 2025-12-01: disclosed
- 2025-11-25: patched: Fixed in v1.4.2
References
- https://github.com/better-auth/better-auth/security/advisories/GHSA-569q-mpph-wgww
- https://github.com/ray-project/ray/commit/70e7c72780bdec075dba6cad1afe0832772bfe09
- https://github.com/better-auth/better-auth
- https://github.com/better-auth/better-auth/releases/tag/v1.4.2
- https://www.vulncheck.com/advisories/better-auth-before-basepath-modification-dos