Skip to content

[GHSA-x732-6j76-qmhm] Better Auth's rou3 Dependency has Double-Slash Path Normalization which can Bypass disabledPaths Config and Rate Limits - #8945

Open
FROWNINGdev wants to merge 1 commit into
github:FROWNINGdev/advisory-improvement-8945from
FROWNINGdev:frowningdev-GHSA-x732-6j76-qmhm
Open

[GHSA-x732-6j76-qmhm] Better Auth's rou3 Dependency has Double-Slash Path Normalization which can Bypass disabledPaths Config and Rate Limits#8945
FROWNINGdev wants to merge 1 commit into
github:FROWNINGdev/advisory-improvement-8945from
FROWNINGdev:frowningdev-GHSA-x732-6j76-qmhm

Conversation

@FROWNINGdev

Copy link
Copy Markdown

Updates

  • Aliases (CVE ID)

Comments
Add CVE-2025-71399 as an alias for this advisory.

The unreviewed record GHSA-9fq7-6g6p-g9rm describes the same vulnerability — rou3 normalizing away empty path segments so that /path, //path and ///path resolve to the same route, allowing disabledPaths and path-based rate limits to be bypassed, fixed in Better Auth 1.4.5 which bundles the patched rou3 — and lists this advisory as its first reference. The two records are duplicates of a single issue, split across keys: this one carries the package mapping (npm:better-auth, < 1.4.5) but no CVE ID, while the unreviewed record carries CVE-2025-71399 but no affected package or version data.

One additional note that may help curation: the unreviewed record lists the fix as better-auth@f60b43fa648399534507c9ac7db36d705b8874c3, but that commit does not exist in better-auth/better-auth. Per the details of this advisory, it is a commit in the upstream router library, h3js/rou3@f60b43fa648399534507c9ac7db36d705b8874c3.

This change is limited to the aliases field; no other fields are touched.

References

@github-actions
github-actions Bot changed the base branch from main to FROWNINGdev/advisory-improvement-8945 August 2, 2026 17:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant