@better-auth/sso is vulnerable to Allocation of Resources Without Limits or Throttling
52
Medium Risk
Affected versions of this package are vulnerable to Denial of Service (DoS) due to Missing Size Limits in SAML handling. The system did not enforce restrictions on the size of incoming SAML responses or Identity Provider (IdP) metadata, allowing an attacker to submit large payloads to consume server resources, potentially leading to service degradation or complete unavailability.
You are affected if you are using a version that falls within the vulnerable range.
@better-auth/sso is vulnerable to Allocation of Resources Without Limits or Throttling in versions 1.4.0 - 1.4.9.
Upgrade the @better-auth/sso library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant