SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2025-71401

MEDIUM · CVSS 5.9 EPSS 0.26% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-02 · Last synced 2026-09-01

CyberRota Analysis

AI-Generated

An external request can manipulate the baseURL configuration in better-auth (npm) versions prior to 1.4.2, leading to a denial of service by causing all routes to return 404 errors. This vulnerability primarily affects deployments where the BETTER_AUTH_URL is unset and the server has just started, making it critical for developers and system administrators using this package to prioritize patching or configuring the baseURL explicitly. Users on managed hosting platforms or those with a defined baseURL are not impacted.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2025-71401
Severity
MEDIUM
CVSS
5.9
EPSS
0.26%

Original NVD Description

better-auth (npm) before 1.4.2 allows an external request to configure baseURL when it is not otherwise defined (e.g., BETTER_AUTH_URL is unset). An attacker able to make the very first request to the server after startup can poison the router's base path, causing all routes to return 404 for all users (denial of service). The issue is not reachable when baseURL is explicitly configured or on typical managed hosting platforms.