CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2025-71399

highCVSS 8.6covered by 1 sourcefirst seen 2026-08-02
Better Auth relies on better-call, which uses the rou3 router library. In affected versions of rou3, paths are normalized by removing empty segments, so /path, //path, and ///path resolve to the same route. In Better Auth versions prior to 1.4.5 (which bundles the fixed rou3), this can allow attackers to bypass disabledPaths configuration and path-based rate limits by submitting requests with extra slashes in the URL path. The issue does not apply in deployments where the proxy or platform normalizes URLs by collapsing multiple slashes.

⚡ Watch CVE-2025-71399

Get an email if CVE-2025-71399 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Advisory coverage (1)

External references

NVD record for CVE-2025-71399

CVE.org record

Embed the live status

CVE-2025-71399 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2025-71399 status](https://www.csirts.com/badge/CVE-2025-71399)](https://www.csirts.com/cve/CVE-2025-71399)