THREATOPS
THREAT OPSThreat News › [NVD] CVE-2025-71399 (HIGH 8.6) — Better Auth relies on better-call, which uses the rou3 router library. In affected versions of rou3, paths are normalized by removing empty segments, so /path, //path, and ///path resolve to the same route. In Better Auth versions prior to 1.4.5 (which bundles the fixed rou3), th

[NVD] CVE-2025-71399 (HIGH 8.6) — Better Auth relies on better-call, which uses the rou3 router library. In affected versions of rou3, paths are normalized by removing empty segments, so /path, //path, and ///path resolve to the same route. In Better Auth versions prior to 1.4.5 (which bundles the fixed rou3), th

mednvdPublished 2026-08-02

CVE-2025-71399 CVSS: 8.6 HIGH Published: 2026-08-02T13:16:52.210

Better Auth relies on better-call, which uses the rou3 router library. In affected versions of rou3, paths are normalized by removing empty segments, so /path, //path, and ///path resolve to the same route. In Better Auth versions prior to 1.4.5 (which bundles the fixed rou3), this can allow attackers to bypass disabledPaths configu

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-71399