Intel

AIKIDO-2026-10012

@better-auth/sso is vulnerable to Allocation of Resources Without Limits or Throttling

Allocation of Resources Without Limits or Throttling Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Jan 8, 2026

52

Medium Risk

This Affects:

JS@better-auth/sso
1.4.0 - 1.4.9
Fixed in 1.4.10
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to Denial of Service (DoS) due to Missing Size Limits in SAML handling. The system did not enforce restrictions on the size of incoming SAML responses or Identity Provider (IdP) metadata, allowing an attacker to submit large payloads to consume server resources, potentially leading to service degradation or complete unavailability.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

@better-auth/sso is vulnerable to Allocation of Resources Without Limits or Throttling in versions 1.4.0 - 1.4.9.

How to fix this

Upgrade the @better-auth/sso library to the patch version.