Known Vulnerabilities for Oauth-provider by Better-auth
Listed below are 10 of the newest known vulnerabilities associated with "Oauth-provider" by "Better-auth".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-49757 json | Authentication Bypass by Spoofing vulnerability in team-alembic AshAuthentication allows account takeover of local users via ... | Not Provided | 2026-06-15 | 2026-06-15 |
| CVE-2026-44707 json | Chatwoot is a customer engagement suite. From 2.14.0 to before 4.13.0, a Pre-Account Takeover (Pre-ATO) vulnerability existed... | Not Provided | 2026-05-26 | 2026-05-26 |
| CVE-2026-44653 json | LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.8.3, users with... | Not Provided | 2026-06-02 | 2026-06-03 |
| CVE-2026-42565 json | @workos/authkit-session is a toolkit for building WorkOS AuthKit framework integrations. Prior to 0.5.1, an open redirect vul... | Not Provided | 2026-05-11 | 2026-05-12 |
| CVE-2026-42560 json | auth provides authentication via oauth2, direct and email. From versions 1.18.0 to before 1.25.2 and 2.0.0 to before 2.1.2, t... | Not Provided | 2026-05-09 | 2026-05-11 |
| CVE-2026-41574 json | Nhost is an open source Firebase alternative with GraphQL. Prior to version 0.49.1, Nhost automatically links an incoming OAu... | Not Provided | 2026-05-08 | 2026-05-08 |
| CVE-2026-41194 json | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, the mailbox OAuth disconnect action i... | Not Provided | 2026-04-21 | 2026-04-22 |
| CVE-2026-41005 json | Cloud Foundry UAA incorrectly treated XML encryption to the Service Provider (confidentiality) as a substitute for XML signat... | Not Provided | 2026-06-11 | 2026-06-11 |
| CVE-2026-35408 json | Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, Directus's Single Sign-On ... | Not Provided | 2026-04-06 | 2026-04-07 |
| CVE-2026-34969 json | Nhost is an open source Firebase alternative with GraphQL. Prior to 0.48.0, the auth service's OAuth provider callback flow p... | Not Provided | 2026-04-06 | 2026-04-07 |