CVE-2026-30964
web-auth/webauthn-lib is an open source set of PHP libraries and a Symfony bundle to allow developers to integrate that authentication mechanism into their web applications. Prior to 5.2.4, when allowed_origins is configured, CheckAllowedOrigins reduces URL-like values to their host component and accepts on host match alone. This makes exact origin policies impossible to express: scheme and port differences are silently ignored. This vulnerability is fixed in 5.2.4.
Published:Mar 10, 2026
Last Modified:May 7, 2026
EPS:Mar 10, 2026
EPSS Score:0.00008
CVSS Score:5.4
Affected Products
Vendor
Product
Action
Vendor
Spomky-labs
Product
Webauthn-lib
Spomky-labs
Webauthn-lib
Vendor
Spomky-labs
Product
Webauthn-symfony-bundle
Spomky-labs
Webauthn-symfony-bundle
Vendor
Spomky-labs
Product
Webauthn Framwork
Spomky-labs
Webauthn Framwork
Vendor
Web-auth
Product
Webauthn-framework
Web-auth
Webauthn-framework
Vendor
Web-auth
Product
Webauthn-lib
Web-auth
Webauthn-lib
Vendor
Web-auth
Product
Webauthn-symfony-bundle
Web-auth
Webauthn-symfony-bundle
Exploits
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
