MEDIUM5.4Packagist
GHSA-f7pm-6hr8-7ggm· CVE-2026-30964Webauthn Framework: allowed_origins collapses URL-like origins to host-only values, bypassing exact origin validation
Modified: 9/10/2026
package
pkg:packagist/web-auth/webauthn-symfony-bundle
Webauthn Framework: allowed_origins collapses URL-like origins to host-only values, bypassing exact origin validation
Modified: 9/10/2026
WebauthnAuthenticator leaks sensitive HTTP headers through INFO-level logs
Modified: 9/10/2026