Intel

AIKIDO-2025-10311

better-auth is vulnerable to Timing Attacks

Timing Attacks Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published May 16, 2025

45

Medium Risk

This Affects:

JSbetter-auth
0.0.1 - 1.2.7
Fixed in 1.2.8
Are you affected? Scan for Free

TL;DR

Affected versions of this package may expose valid email addresses due to inconsistent response times during authentication. The patched version mitigates this by hashing passwords even when email addresses are invalid, ensuring uniform response times and preventing timing attacks that could reveal the existence of user accounts.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

better-auth is vulnerable to Timing Attacks in versions 0.0.1 - 1.2.7.

How to fix this

Upgrade the better-auth library to the patch version.