MEDIUM5.3Packagist
GHSA-875x-g8p7-5w27· CVE-2024-39912The FIDO2/Webauthn Support for PHP library allows enumeration of valid usernames
Modified: 9/10/2026
package
pkg:packagist/web-auth/webauthn-lib
The FIDO2/Webauthn Support for PHP library allows enumeration of valid usernames
Modified: 9/10/2026
Webauthn Framework: allowed_origins collapses URL-like origins to host-only values, bypassing exact origin validation
Modified: 9/10/2026
Webauthn: SimpleFakeCredentialGenerator with an empty secret produces predictable fake credentials, weakening username enumeration protection
Modified: 9/10/2026