@better-auth/oauth-provider vulnerabilities
CVEs whose affected-version data names the @better-auth/oauth-provider package (npm). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
GHSA-p2fr-6hmx-4528Medium· 6.4@better-auth/oauth-provider may provide access tokens for unauthorized audiences via unbound resource indicators
@better-auth/oauth-provider may provide access tokens for unauthorized audiences via unbound resource indicators
▾ Sunlitbetter-auth · @better-auth/oauth-providervia GHSA
CVE-2026-53517High· 8.1Better Auth: OAuth refresh-token rotation forks the token family on concurrent redemption
Better Auth: OAuth refresh-token rotation forks the token family on concurrent redemption
▾ Twilightbetter-auth · @better-auth/oauth-providerEPSS 0.42%via GHSA
CVE-2026-53518High· 8.1@better-auth/oauth-provider's OAuth authorization-code grant allows concurrent redemption when two token requests race the find-then-delete primitive
@better-auth/oauth-provider's OAuth authorization-code grant allows concurrent redemption when two token requests race the find-then-delete primitive
▾ Twilightbetter-auth · @better-auth/oauth-providerEPSS 0.41%via GHSA