CVE Feed

    Dashboard / CVE / CVE-2026-30964

    CVE-2026-30964

    web-auth/webauthn-lib is an open source set of PHP libraries and a Symfony bundle to allow developers to integrate that authentication mechanism into their web applications. Prior to 5.2.4, when allowed_origins is configured, CheckAllowedOrigins reduces URL-like values to their host component and accepts on host match alone. This makes exact origin policies impossible to express: scheme and port differences are silently ignored. This vulnerability is fixed in 5.2.4.

    Published:Mar 10, 2026
    Last Modified:May 7, 2026
    EPS:Mar 10, 2026
    EPSS Score:0.00008
    CVSS Score:5.4

    Affected Products

    Vendor
    Spomky-labs
    Product
    Webauthn-lib
    Vendor
    Spomky-labs
    Product
    Webauthn-symfony-bundle
    Vendor
    Spomky-labs
    Product
    Webauthn Framwork
    Vendor
    Web-auth
    Product
    Webauthn-framework
    Vendor
    Web-auth
    Product
    Webauthn-lib
    Vendor
    Web-auth
    Product
    Webauthn-symfony-bundle

    Common Weakness Enumeration

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High