Junglewise Threat Intelligence

CVE-2026-30964: Webauthn Framework: allowed_origins collapses URL-like origins to host-only values, bypassing exact origin validation

CVE-2026-30964 · Severity: low · CVSS 3.1 · Published 2026-03-10

Technologies: web-auth/webauthn-framework (Packagist), web-auth/webauthn-symfony-bundle (Packagist), web-auth/webauthn-lib (Packagist). Vendors: Packagist.

Executive brief

Webauthn Framework: allowed_origins collapses URL-like origins to host-only values, bypassing exact origin validation

Affected products

  • Packagist web-auth/webauthn-framework
  • Packagist web-auth/webauthn-symfony-bundle
  • Packagist web-auth/webauthn-lib

Related threats