better-auth is vulnerable to Information Disclosure
39
Low Risk
The unauthenticated /send-verification-email endpoint returns quickly when an email is unknown or already verified but waits for the configured email callback when the address belongs to an unverified user. Remote callers could compare response times to learn whether an address is registered and pending verification. The patch enforces a 500ms minimum response time on the unauthenticated path and surfaces sendVerificationEmail failures after that delay.
You are affected if you are using a version that falls within the vulnerable range and expose the unauthenticated /send-verification-email endpoint with email verification enabled.
better-auth is vulnerable to Information Disclosure in versions 1.5.0 - 1.6.18.
Upgrade the better-auth library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant