Known Vulnerabilities for Better Auth by Better-auth
Listed below are 8 of the newest known vulnerabilities associated with "Better Auth" by "Better-auth".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-102876 json | SurrealDB before 3.3.0 contains an authorization bypass in HTTP session construction where check_auth() verifies credentials ... | Not Provided | 2026-09-29 | 2026-09-29 |
| CVE-2026-101283 json | iperf3 3.20–3.21 (esnet/iperf) has a pre-auth heap buffer overflow in decrypt_rsa_message(): a 256-byte RSA buffer is BIO_r... | Not Provided | 2026-09-30 | 2026-09-30 |
| CVE-2026-101057 json | utcp-mcp (the MCP plugin of python-utcp) through 1.1.2 connects to the HTTP and WebSocket MCP server URLs given in a call tem... | Not Provided | 2026-09-27 | 2026-09-30 |
| CVE-2026-101042 json | Parse Server is an open-source backend server. In versions >= 9.0.0 < 9.10.1-alpha.10 and >= 8.0.2 < 8.6.91, the code-based a... | Not Provided | 2026-09-27 | 2026-09-30 |
| CVE-2026-100862 json | heym, a workflow automation platform, stores and returns multiple capability secrets in plaintext in versions prior to 0.0.91... | Not Provided | 2026-09-27 | 2026-09-30 |
| CVE-2026-100837 json | Contrast (Edgeless Systems) through 1.20.0 performs unanchored suffix matching when selecting per-registry configuration in t... | Not Provided | 2026-09-27 | 2026-09-28 |
| CVE-2026-100741 json | Eval injection in the JScript event-script dispatcher in Progressive Robot Ltd's hMailServer, versions 6.0.0 through 6.3.3 on... | Not Provided | 2026-09-27 | 2026-09-28 |
| CVE-2026-100698 json | Adminer 5.5.1 through 6.0.1 improperly parses the login 'server' string in the host_port() function in adminer/include/functi... | Not Provided | 2026-09-26 | 2026-09-30 |
| CVE-2026-100697 json | Adminer 6.0.0 through 6.0.1, when the official ClickHouse driver plugin (plugins/drivers/clickhouse.php, rewritten in 6.0.0) ... | Not Provided | 2026-09-26 | 2026-09-30 |
| CVE-2026-100696 json | Adminer 4.16.0 through 6.0.1 contain a pre-authentication Server-Side Request Forgery (SSRF) vulnerability in the optional El... | Not Provided | 2026-09-26 | 2026-09-28 |