{"api_version":"v1","generated_at":"2026-10-08T01:45:00+00:00","product":{"cve_count":25,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-better-auth-better-auth-339b771adeca","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/better-auth","name":"better-auth","next_cursor":null,"observations":[{"affected":"better-auth: < 1.4.2","affected_versions_present":true,"cve_id":"CVE-2025-71401","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-71401","fixed":"better-auth: 1.4.2","last_modified":"2026-08-03T14:29:35.454Z","patch_url":"https://github.com/better-auth/better-auth/security/advisories/GHSA-569q-mpph-wgww","primary_source":"","published":"2026-08-02T12:15:23.707Z"},{"affected":"better-auth: < 1.4.5","affected_versions_present":true,"cve_id":"CVE-2025-71399","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-71399","fixed":"better-auth: 1.4.5","last_modified":"2026-08-03T15:50:52.728Z","patch_url":"https://github.com/better-auth/better-auth/security/advisories/GHSA-x732-6j76-qmhm","primary_source":"","published":"2026-08-02T12:15:22.129Z"},{"affected":"< 1.6.11","affected_versions_present":true,"cve_id":"CVE-2026-67336","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-67336","fixed":"1.6.11","last_modified":"2026-08-03T15:23:44.055Z","patch_url":"https://github.com/better-auth/better-auth/security/advisories/GHSA-9h47-pqcx-hjr4","primary_source":"","published":"2026-08-01T12:22:18.271Z"},{"affected":"< 1.6.13; 1.7.0-beta.0 < 1.7.0-beta.4","affected_versions_present":true,"cve_id":"CVE-2026-67333","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-67333","fixed":"1.6.13; 1.7.0-beta.4","last_modified":"2026-08-03T19:43:05.018Z","patch_url":"https://github.com/better-auth/better-auth/security/advisories/GHSA-86j7-9j95-vpqj","primary_source":"","published":"2026-08-01T12:22:18.167Z"},{"affected":"0.3.4 < 1.6.11; 1.6.0 < 1.6.11","affected_versions_present":true,"cve_id":"CVE-2026-67334","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-67334","fixed":"1.6.11","last_modified":"2026-08-03T18:19:22.119Z","patch_url":"https://github.com/better-auth/better-auth/security/advisories/GHSA-2vg6-77g8-24mp","primary_source":"","published":"2026-08-01T12:22:18.107Z"},{"affected":"better-auth: < 1.1.20","affected_versions_present":true,"cve_id":"CVE-2025-71403","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-71403","fixed":"better-auth: 1.1.20","last_modified":"2026-08-03T18:18:54.122Z","patch_url":"https://github.com/better-auth/better-auth/security/advisories/GHSA-vp58-j275-797x","primary_source":"","published":"2026-08-01T12:22:18.102Z"},{"affected":"< 1.4.9","affected_versions_present":true,"cve_id":"CVE-2026-67337","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-67337","fixed":"1.4.9","last_modified":"2026-08-03T18:31:13.051Z","patch_url":"https://github.com/better-auth/better-auth/security/advisories/GHSA-xg6x-h9c9-2m83","primary_source":"","published":"2026-08-01T12:22:18.034Z"},{"affected":"better-auth: < 1.1.16","affected_versions_present":true,"cve_id":"CVE-2025-71404","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-71404","fixed":"better-auth: 1.1.16","last_modified":"2026-08-03T15:38:00.141Z","patch_url":"https://github.com/better-auth/better-auth/security/advisories/GHSA-9x4v-xfq5-m8x5","primary_source":"","published":"2026-08-01T12:22:17.885Z"},{"affected":"1.1.3 < 1.6.22; 1.7.0-beta.0 < 1.7.0-beta.10","affected_versions_present":true,"cve_id":"CVE-2026-67327","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-67327","fixed":"1.6.22; 1.7.0-beta.10","last_modified":"2026-08-03T18:29:37.617Z","patch_url":"https://github.com/better-auth/better-auth/security/advisories/GHSA-qq9h-g4jm-xgf3","primary_source":"","published":"2026-08-01T12:22:17.753Z"},{"affected":"< 1.6.2","affected_versions_present":true,"cve_id":"CVE-2026-67335","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-67335","fixed":"1.6.2","last_modified":"2026-08-03T15:38:08.522Z","patch_url":"https://github.com/better-auth/better-auth/security/advisories/GHSA-wxw3-q3m9-c3jr","primary_source":"","published":"2026-08-01T12:22:17.178Z"},{"affected":"better-auth: < 1.4.0","affected_versions_present":true,"cve_id":"CVE-2025-71402","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-71402","fixed":"better-auth: 1.4.0","last_modified":"2026-08-03T19:32:01.754Z","patch_url":"https://github.com/better-auth/better-auth/security/advisories/GHSA-wmjr-v86c-m9jj","primary_source":"","published":"2026-08-01T12:22:16.655Z"},{"affected":">= 1.4.8-beta.7, < 1.6.0; >= 1.6.0, < 1.6.11","affected_versions_present":true,"cve_id":"CVE-2026-53517","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-53517","fixed":"1.6.11.","last_modified":"2026-07-15T19:21:22.553Z","patch_url":"https://github.com/better-auth/better-auth/commit/c6918ecc9e3a75892169415d7f6c95b591b6a52d","primary_source":"","published":"2026-07-15T17:33:38.943Z"},{"affected":">= 1.6.0, < 1.6.11","affected_versions_present":true,"cve_id":"CVE-2026-45337","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-45337","fixed":"1.6.11.","last_modified":"2026-07-15T18:02:58.506Z","patch_url":"https://github.com/better-auth/better-auth/pull/9573","primary_source":"","published":"2026-07-15T17:31:44.983Z"},{"affected":"< 1.6.11","affected_versions_present":true,"cve_id":"CVE-2026-53514","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-53514","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-07-18T01:13:02.175Z","patch_url":"https://github.com/better-auth/better-auth/pull/9577","primary_source":"","published":"2026-07-15T17:30:46.069Z"},{"affected":">= 1.2.10, < 1.6.11","affected_versions_present":true,"cve_id":"CVE-2026-53515","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-53515","fixed":"1.6.11.","last_modified":"2026-07-15T19:30:08.165Z","patch_url":"https://github.com/better-auth/better-auth/pull/9220","primary_source":"","published":"2026-07-15T17:27:00.291Z"},{"affected":"< 1.6.11","affected_versions_present":true,"cve_id":"CVE-2026-53512","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-53512","fixed":"1.6.11.","last_modified":"2026-07-18T01:08:08.419Z","patch_url":"https://github.com/better-auth/better-auth/pull/9576","primary_source":"","published":"2026-07-15T17:18:09.512Z"},{"affected":">= 1.6.0, < 1.6.11","affected_versions_present":true,"cve_id":"CVE-2026-53518","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-53518","fixed":"1.6.11.","last_modified":"2026-07-15T18:07:49.190Z","patch_url":"https://github.com/better-auth/better-auth/commit/b4bc65a007784b2eb0efb459e5fa6fd8055d3ec9","primary_source":"","published":"2026-07-15T17:17:06.410Z"},{"affected":">= 0.1.0, < 1.6.11","affected_versions_present":true,"cve_id":"CVE-2026-53513","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-53513","fixed":"1.6.11.","last_modified":"2026-07-15T19:29:02.266Z","patch_url":"https://github.com/better-auth/better-auth/pull/9574","primary_source":"","published":"2026-07-15T17:15:59.611Z"},{"affected":"< 1.6.11","affected_versions_present":true,"cve_id":"CVE-2026-53516","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-53516","fixed":"1.6.11.","last_modified":"2026-07-15T17:52:35.572Z","patch_url":"https://github.com/better-auth/better-auth/pull/9578","primary_source":"","published":"2026-07-15T17:13:16.431Z"},{"affected":"< 1.4.17; >= 1.5.0-beta.1, < 1.5.0-beta.9","affected_versions_present":true,"cve_id":"CVE-2026-45364","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-45364","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-29T19:05:38.845Z","patch_url":"","primary_source":"","published":"2026-05-28T21:34:51.446Z"},{"affected":">= 1.4.8-beta.7, < 1.6.5; >= 1.7.0-beta.0, <= 1.7.0-beta.1","affected_versions_present":true,"cve_id":"CVE-2026-41427","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-41427","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-27T13:42:23.885Z","patch_url":"https://github.com/better-auth/better-auth/security/advisories/GHSA-xr8f-h2gw-9xh6","primary_source":"","published":"2026-04-24T19:23:20.161Z"},{"affected":"< 1.3.26","affected_versions_present":true,"cve_id":"CVE-2025-61928","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-61928","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-10-10T14:23:23.158Z","patch_url":"","primary_source":"","published":"2025-10-09T21:24:37.541Z"},{"affected":"< 1.2.10","affected_versions_present":true,"cve_id":"CVE-2025-53535","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-53535","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-07-07T17:48:36.223Z","patch_url":"","primary_source":"","published":"2025-07-07T17:15:52.027Z"},{"affected":"< 1.1.20","affected_versions_present":true,"cve_id":"CVE-2025-27143","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-27143","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-02-25T14:29:03.293Z","patch_url":"https://github.com/better-auth/better-auth/commit/24659aefc35a536b95ea4e5347e52c8803910153","primary_source":"","published":"2025-02-24T22:16:55.224Z"},{"affected":"< 1.1.5","affected_versions_present":true,"cve_id":"CVE-2024-56734","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-56734","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-12-30T17:36:51.332Z","patch_url":"https://github.com/better-auth/better-auth/commit/deb3d73aea90d0468d92723f4511542b593e522f","primary_source":"","published":"2024-12-30T16:48:58.184Z"}],"source_generated_at":"2026-10-07T06:21:30.017Z","vendor":"better-auth"}}
