Security: web-auth/webauthn-framework
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
SimpleFakeCredentialGenerator with an empty secret produces predictable fake credentials, weakening username enumeration protectionGHSA-gq4g-fpc9-vjfq published
May 31, 2026 by SpomkyLow -
Sensitive HTTP headers leaked through INFO-level logs in WebauthnAuthenticatorGHSA-q683-8468-r6h6 published
May 24, 2026 by SpomkyModerate -
User Verification Downgrade via Default-Open ClientOverridePolicyGHSA-h4fw-6r7f-w494 published
May 2, 2026 by SpomkyLow -
allowed_origins collapses URL-like origins to host-only values, bypassing exact origin validationGHSA-f7pm-6hr8-7ggm published
Mar 8, 2026 by SpomkyModerate -
Enumeration of valid usernamesGHSA-875x-g8p7-5w27 published
Jul 14, 2024 by SpomkyModerate