Webauthn-Framework
Web-Auth · 2 CVEs
CVE-2026-30964
MEDIUM
Webauthn Framework: allowed_origins collapses URL-like origins to host-only values, bypassing exact origin validation
Mar 10, 2026
CVE-2024-39912
MEDIUM
Enumeration of valid usernames in web-auth/webauthn-lib
Jul 15, 2024
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-30964 | Webauthn Framework: allowed_origins collapses URL-like origins to host-only values, bypassing exact origin validation | MEDIUM | 0.19% | Mar 10, 2026 |
| CVE-2024-39912 | Enumeration of valid usernames in web-auth/webauthn-lib | MEDIUM | 0.39% | Jul 15, 2024 |
Showing 1 to 2 of 2 CVEs