Vuln
·
Scope
Home
Packages
KEV
Critical
Insights
EN
中
Loading…
Packagist/web-auth/webauthn-framework — 3 CVEs · VulnScope
pkg:Packagist/
web-auth/webauthn-framework
3 total CVEs
CRITICAL
1
MEDIUM
2
✅ Check your installed version
Check
All known vulnerabilities
CRITICAL
9.8
CVE-2021-38299
Improper Access Control in Webauthn Framework
>= 3.3.0, < 3.3.4
MEDIUM
5.4
CVE-2026-30964
Webauthn Framework: allowed_origins collapses URL-like origins to host-only values, bypassing exact origin validation
>= 5.2.0, < 5.2.4
MEDIUM
5.3
CVE-2024-39912
The FIDO2/Webauthn Support for PHP library allows enumeration of valid usernames
>= 4.5.0, < 4.9.0