A vulnerability was found in better-auth up to 1.4.1. It has been rated as critical. Impacted is an unknown function. This manipulation causes resource consumption.

This vulnerability is tracked as CVE-2025-71401. The attack is possible to be carried out remotely. No exploit exists.

Upgrading the affected component is advised.