better-auth is vulnerable to Timing Attacks
45
Medium Risk
Affected versions of this package may expose valid email addresses due to inconsistent response times during authentication. The patched version mitigates this by hashing passwords even when email addresses are invalid, ensuring uniform response times and preventing timing attacks that could reveal the existence of user accounts.
You are affected if you are using a version that falls within the vulnerable range.
better-auth is vulnerable to Timing Attacks in versions 0.0.1 - 1.2.7.
Upgrade the better-auth library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant