CVE-2026-30964 affects web-auth/webauthn-lib versions prior to 5.2.4, a PHP library for WebAuthn integration. The vulnerability, classified as CWE-346, involves an insufficient origin validation flaw where the CheckAllowedOrigins function incorrectly reduces URL-like values to their host component, ignoring scheme and port differences. Rated as medium severity (CVSS 5.4), it could lead to low confidentiality and integrity impacts by allowing bypasses of exact origin policies, requiring user interaction for exploitation. There is currently no evidence of active exploitation, public exploit code, or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.2.0, < 5.2.4CPE matchmatch criteria | cpe:2.3:a:spomky-labs:webauthn-lib:*:*:*:*:*:*:*:* | ||
>= 5.2.0, < 5.2.4CPE matchmatch criteria | cpe:2.3:a:spomky-labs:webauthn-symfony-bundle:*:*:*:*:*:*:*:* | ||
>= 5.2.0, < 5.2.4CPE matchmatch criteria | cpe:2.3:a:spomky-labs:webauthn_framwork:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.