Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

better-auth versions after v0.0.2 and before 1.1.16 contain a reflected cross-site scripting (XSS) vulnerability on the /api/auth/error page, where… (CVE-2025-71404)CVE-2025-71404
0

better-auth versions after 0.0.2 and before 1.1.16 have a reflected cross-site scripting (XSS) vulnerability on the /api/auth/error page. The vulnerability arises because the 'error' URL parameter is reflected in the HTML response without proper neutralization, allowing an attacker to execute arbitrary JavaScript in the user's browser if the user visits a crafted URL. This issue is fixed in version 1.1.16.

Join the discussion
better-auth versions before 1.1.20 contain a bypass vulnerability in trustedOrigins validation logic affecting absolute URLs and wildcard domains. (CVE-2025-71403)CVE-2025-71403
0

better-auth versions before 1.1.20 have a vulnerability in the trustedOrigins validation logic that allows bypassing origin checks for absolute URLs and wildcard domains. This flaw enables attackers to craft malicious callbackURL parameters that can trigger open redirects. Exploiting this can lead to theft of sensitive tokens and potential account takeover. The vulnerability is categorized under CWE-601 (Open Redirect). It has a CVSS 3.1 score of 7.1, indicating high severity. No patch or fix information is currently provided.

Join the discussion
better-auth versions greater than 1.3.34 and before 1.4.0 contain a vulnerability in the multi-session plugin's /sign-out after-hook, which trusts… (CVE-2025-71402)CVE-2025-71402
0

better-auth versions greater than 1.3.34 and before 1.4.0 have a vulnerability in the multi-session plugin's /sign-out after-hook. The vulnerability arises because the after-hook trusts raw multi-session cookies and forwards extracted values to internalAdapter.deleteSessions without verifying the cookie signature. This allows an attacker to supply a forged _multi-* cookie to delete arbitrary session tokens.

Join the discussion
better-auth versions >= 1.1.3 and < 1.6.22 (and pre-release versions >= 1.7.0-beta.0 and < 1.7.0-beta.10) are vulnerable to account takeover via… (CVE-2026-67327)CVE-2026-67327
0

better-auth versions from 1.1.3 up to but not including 1.6.22, and pre-release versions from 1.7.0-beta.0 up to but not including 1.7.0-beta.10, contain a vulnerability that allows account takeover via a pre-account hijacking attack. This occurs when open email/password registration is enabled and an attacker registers an account with the victim's email and a chosen password. Later, when the legitimate user signs in using magic-link or email-OTP passwordless methods, the account becomes verified without removing the attacker's password or revoking sessions, allowing persistent unauthorized access. The issue is fixed in versions 1.6.22 and 1.7.0-beta.10.

Join the discussion
better-auth versions before 1.6.2 fail to validate the OAuth state parameter against the stored nonce when using cookie-backed state storage without… (CVE-2026-67335)CVE-2026-67335
0

better-auth versions before 1.6.2 contain a vulnerability where the OAuth state parameter is not properly validated against the stored nonce when using cookie-backed state storage without PKCE. This flaw allows attackers to forge the state parameter and supply an attacker-controlled authorization code, potentially creating authenticated sessions tied to the attacker's identity or linking attacker accounts to victim profiles. The vulnerability has a CVSS score of 5.3, indicating medium severity.

Join the discussion
better-auth versions before 1.4.9 contain a two-factor authentication bypass vulnerability when session.cookieCache is enabled. (CVE-2026-67337)CVE-2026-67337
0

better-auth versions before 1.4.9 have a vulnerability that allows bypassing two-factor authentication when session.cookieCache is enabled. Attackers who have valid primary credentials can access authenticated routes without completing the second-factor verification due to premature session caching.

Join the discussion
better-auth versions before 1.6.11 fail to delete cached sessions when removing users via admin, anonymous, or SCIM endpoints when secondaryStorage… (CVE-2026-67334)CVE-2026-67334
0

better-auth versions before 1.6.11 have a vulnerability where cached user sessions are not deleted when users are removed via admin, anonymous, or SCIM endpoints if secondaryStorage is configured and storeSessionInDatabase is false. This allows attackers to reuse deleted user session tokens to maintain authentication for up to seven days after the account deletion. The issue has a medium severity with a CVSS score of 3.8.

Join the discussion
better-auth versions before 1.6.11 contain insecure cryptographic defaults in the oidcProvider and mcp plugins that advertise the none algorithm and… (CVE-2026-67336)CVE-2026-67336
0

better-auth versions before 1.6.11 have insecure cryptographic defaults in the oidcProvider and mcp plugins. These defaults advertise the 'none' algorithm and accept plain PKCE by default, which can be exploited by attackers to accept unsigned tokens or intercept authorization codes. This vulnerability affects the security of token validation and authorization code exchange.

Join the discussion
better-auth before 1.6.13 (and pre-release builds 1.7.0-beta.0 through 1.7.0-beta.3) fail to validate the scheme of redirect_uris registered via the… (CVE-2026-67333)CVE-2026-67333
0

better-auth versions before 1.6.13 and pre-release builds 1.7.0-beta.0 through 1.7.0-beta.3 contain a vulnerability where the scheme of redirect_uris registered via certain plugins is not validated. This allows an attacker to register an OAuth client with a javascript: redirect_uri, which can lead to execution of attacker-controlled JavaScript in the authorization server's origin, potentially exposing user sessions and enabling account takeover.

Join the discussion

Showing 1 to 9 of 9 results

Filters:Package: pkg:github/better-auth/better-auth
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses