CVE-2026-45364
📛 CVE Title
(no title)
Description
Better Auth: Rate limiter keys IPv6 addresses individually and is bypassable via prefix rotation
Description (MITRE) cveawg.mitre.org
Pulled from cveawg.mitre.org/api/cve/CVE-2026-45364 on 2026-07-28. Shown when MITRE's text differs from the cvelistV5 mirror.
Better Auth is an authentication and authorization library for TypeScript. Prior to 1.4.17 and 1.5.0-beta.9, Better Auth's HTTP rate limiter keyed each request by the exact textual IP address it received in x-forwarded-for (or the configured IP-bearing header). IPv6 clients controlling a typical /64 allocation could rotate through 2^64 distinct source addresses without exhausting the per-address counter, defeating rate limiting on /sign-in/email, /sign-up/email, /forget-password, and every other path the limiter protects. The same bug allowed a single client to vary the textual encoding of one IPv6 address (uppercase, compression, IPv4-mapped, hex-encoded IPv4-in-IPv6) and produce multiple distinct keys. This vulnerability is fixed in 1.4.17 and 1.5.0-beta.9.
Overview
- State
- —
- Assigner (CNA)
- —
- CVSS severity
- high
- CVSS score
- 7.3 / 10
- CVSS vector
AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L- Effective score
- 7.3 / 10 HIGH source: CNA overview
- CWE(s)
- —
- Reserved
- —
- Published
- —
- Last updated
- —
- Source
- https://www.tenable.com/cve/CVE-2026-45364
- Linked Threat
- CVE-2026-45364 — CVE-2026-45364
NVD / KEV / EPSS data refreshed 2026-05-25 00:07 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2026-33073
EUVD enrichment is queued; refresh the page in a few seconds.
Vendor references (0)
References embedded in the original CVE record by the assigning CNA.
None in the CVE record.
Web references (8)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
- https://www.first.org/epss/ tenable:www.first.org
- https://github.com/better-auth/better-auth/commit/57af0f7b910dcf7b1a5c0615d10b9bd56bb69bef tenable:github.com
- https://github.com/better-auth/better-auth/pull/7470 tenable:github.com
- https://github.com/better-auth/better-auth/pull/7509 tenable:github.com
- https://github.com/better-auth/better-auth/security/advisories/GHSA-p6v2-xcpg-h6xw tenable:github.com
- https://github.com/better-auth/better-auth/commit/43e719bcc0c223c7079fa0c611a9cf7ea1188254 tenable:github.com
- https://www.cve.org/CVERecord?id=CVE-2026-45364 tenable:www.cve.org
- https://nvd.nist.gov/vuln/detail/CVE-2026-45364 tenable:nvd.nist.gov
Remediations (10)
Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.
-
web:www.enerbank.com
www.enerbank.com
2026-05-26 02:55 UTC -
web:community.ui.com
Published: May 21, 2026 Updated: May 22, 2026 Version: 1.1 Revision: 1.1 Summary 1 of 5 A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection. Affected Products: UniFi OS Server (Version 5.0.6 and earlier) Mitigation : Update your UniFi OS Server to Version 5.0.8 or later ...
2026-05-26 02:55 UTC -
web:docs.openclaw.ai
Migration checklist Use this checklist when you already know your old BlueBubbles config and want the shortest safe path: Verify imsg directly on the Mac that runs Messages.app (imsg chats, imsg history, imsg send, and imsg rpc --help). Copy behavior keys from channels.bluebubbles to channels.imessage: dmPolicy, allowFrom, groupPolicy, groupAllowFrom, groups, includeAttachments ...
2026-05-26 02:55 UTC -
web:finance.yahoo.com
An Ohio family is pushing back after their insurer says a repair is good enough. Here's why the suggested repair might violate the law.
2026-05-26 02:55 UTC -
web:hi.service-now.com
The Now Support portal is your launchpad to access self-help, get technical support, and manage your ServiceNow instances. Log in to manage upgrades, follow changes, view knowledge content, and more. Formerly HI portal.
2026-05-26 02:55 UTC -
web:onlyfans.com
OnlyFans is the social platform revolutionizing creator and fan connections. The site is inclusive of artists and content creators from all genres and allows them to monetize their content while developing authentic relationships with their fanbase.
2026-05-26 02:55 UTC -
web:robertsspaceindustries.com
Hi Everyone! Time again for another Hotfix Central thread to keep you all up to date on things going on outside of the normal patch cycle in SC Alpha 4.8 LIVE! This will be a living document of...
2026-05-26 02:55 UTC -
web:wa.me
Hosted by WhatsApp 2026 © WhatsApp LLC Privacy & Terms
2026-05-26 02:55 UTC -
web:www.fema.gov
FEMA.gov
2026-05-26 02:55 UTC -
web:www.virustotal.com
VirusTotal is a platform for scanning files and URLs for viruses, malware, and other threats using multiple antivirus engines.
2026-05-26 02:55 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.