Junglewise Threat Intelligence
CVE-2026-30964: Webauthn Framework: allowed_origins collapses URL-like origins to host-only values, bypassing exact origin validation
CVE-2026-30964 · Severity: low · CVSS 3.1 · Published 2026-03-10
Technologies: web-auth/webauthn-framework (Packagist), web-auth/webauthn-symfony-bundle (Packagist), web-auth/webauthn-lib (Packagist). Vendors: Packagist.
Executive brief
Webauthn Framework: allowed_origins collapses URL-like origins to host-only values, bypassing exact origin validation
Affected products
- Packagist web-auth/webauthn-framework
- Packagist web-auth/webauthn-symfony-bundle
- Packagist web-auth/webauthn-lib