{"id":"CVE-2026-45364","aliases":["GHSA-p6v2-xcpg-h6xw"],"url":"https://o3.security/vulnerability/CVE-2026-45364","summary":"Better Auth: Rate limiter keys IPv6 addresses individually and is bypassable via prefix rotation","details":"Better Auth is an authentication and authorization library for TypeScript. Prior to 1.4.17 and 1.5.0-beta.9, Better Auth's HTTP rate limiter keyed each request by the exact textual IP address it received in x-forwarded-for (or the configured IP-bearing header). IPv6 clients controlling a typical /64 allocation could rotate through 2^64 distinct source addresses without exhausting the per-address counter, defeating rate limiting on /sign-in/email, /sign-up/email, /forget-password, and every other path the limiter protects. The same bug allowed a single client to vary the textual encoding of one IPv6 address (uppercase, compression, IPv4-mapped, hex-encoded IPv4-in-IPv6) and produce multiple distinct keys. This vulnerability is fixed in 1.4.17 and 1.5.0-beta.9.","published":"2026-05-28T21:34:51.446Z","modified":"2026-08-12T03:51:35.655223079Z","cvss":{"score":7.3,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"better-auth","fixedVersion":"1.4.17"},{"ecosystem":"npm","name":"better-auth","fixedVersion":"1.5.0-beta.9"}],"fix":{"url":"https://github.com/better-auth/better-auth/commit/43e719bcc0c223c7079fa0c611a9cf7ea1188254","label":"better-auth/better-auth@43e719b"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45364.json"},{"type":"ADVISORY","url":"https://github.com/better-auth/better-auth/security/advisories/GHSA-p6v2-xcpg-h6xw"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45364"},{"type":"FIX","url":"https://github.com/better-auth/better-auth/commit/43e719bcc0c223c7079fa0c611a9cf7ea1188254"},{"type":"FIX","url":"https://github.com/better-auth/better-auth/commit/57af0f7b910dcf7b1a5c0615d10b9bd56bb69bef"},{"type":"FIX","url":"https://github.com/better-auth/better-auth/pull/7470"},{"type":"FIX","url":"https://github.com/better-auth/better-auth/pull/7509"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:35.655223079Z"}}