THREAT OPS › Threat News › [NVD] CVE-2025-71399 (HIGH 8.6) — Better Auth relies on better-call, which uses the rou3 router library. In affected versions of rou3, paths are normalized by removing empty segments, so /path, //path, and ///path resolve to the same route. In Better Auth versions prior to 1.4.5 (which bundles the fixed rou3), th
[NVD] CVE-2025-71399 (HIGH 8.6) — Better Auth relies on better-call, which uses the rou3 router library. In affected versions of rou3, paths are normalized by removing empty segments, so /path, //path, and ///path resolve to the same route. In Better Auth versions prior to 1.4.5 (which bundles the fixed rou3), th
CVE-2025-71399 CVSS: 8.6 HIGH Published: 2026-08-02T13:16:52.210
Better Auth relies on better-call, which uses the rou3 router library. In affected versions of rou3, paths are normalized by removing empty segments, so /path, //path, and ///path resolve to the same route. In Better Auth versions prior to 1.4.5 (which bundles the fixed rou3), this can allow attackers to bypass disabledPaths configu
Indicators of compromise
- CVE-2025-71399cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-71399