Better Auth relies on better-call, which uses the rou3 router library. In affected versions of rou3, paths are normalized by removing empty segments, so /path, //path, and ///path resolve to the same…
高危 CVSS 8.6
摘要
Better Auth relies on better-call, which uses the rou3 router library. In affected versions of rou3, paths are normalized by removing empty segments, so /path, //path, and ///path resolve to the same route. In Better Auth versions prior to 1.4.5 (which bundles the fixed rou3), this can allow attackers to bypass disabledPaths configuration and path-based rate limits by submitting requests with extra slashes in the URL path. The issue does not apply in deployments where the proxy or platform norm…
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判 · 自动通道
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
数据来源
- NVD DATABASE
原始链接
- https://github.com/better-auth/better-auth/commit/f60b43fa648399534507c9ac7db36d705b8874c3
- https://github.com/better-auth/better-auth/security/advisories/GHSA-x732-6j76-qmhm
- https://www.vulncheck.com/advisories/better-auth-before-path-normalization-bypass-via-rou3
时间线
- nvd_ingest NVD