Spomky Labs develops the WebAuthn Framework, a specialized library focused on server-side implementation of Web Authentication standards, with a narrow product scope that positions it as a critical dependency for applications integrating passwordless authentication. The observed vulnerability disclosures center on the protocol-handling layer characteristic of authentication frameworks. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Spomky Labs over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-38299CRITICAL Webauthn Framework 3.3.x before 3.3.4 has Incorrect Access Control. An attacker that controls a user's system is able to login to a vulnerable service using an attached FIDO2 authe | Sep 27, 2021 | 9.8 | 31 | NO | NO |
CVE-2026-30964MEDIUM web-auth/webauthn-lib is an open source set of PHP libraries and a Symfony bundle to allow developers to integrate that authentication mechanism into their web applications. Prior | Mar 10, 2026 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Spomky Labs.
Media articles that mention a CVE ID that affects a product developed by Spomky Labs — matched by CVE ID, not by vendor name.