<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T11:53:06.929455+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-275302</id>
    <title>EUVD-2026-275302</title>
    <updated>2026-10-08T11:53:06.982740+00:00</updated>
    <content>EUVD-2026-275302</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-275302"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-30964</id>
    <title>fkie_cve-2026-30964</title>
    <updated>2026-10-08T11:53:06.982797+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>web-auth/webauthn-lib is an open source set of PHP libraries and a Symfony bundle to allow developers to integrate that authentication mechanism into their web applications. Prior to 5.2.4, when allowed_origins is configured, CheckAllowedOrigins reduces URL-like values to their host component and accepts on host match alone. This makes exact origin policies impossible to express: scheme and port differences are silently ignored. This vulnerability is fixed in 5.2.4.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-30964"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-f7pm-6hr8-7ggm</id>
    <title>GHSA-f7pm-6hr8-7ggm — Webauthn Framework: allowed_origins collapses URL-like origins to host-only values, bypassing exact origin validation</title>
    <updated>2026-10-08T11:53:06.982836+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: web-auth/webauthn-framework, Packagist: web-auth/webauthn-lib, Packagist: web-auth/webauthn-symfony-bundle</p>
<p>### Summary
When `allowed_origins` is configured, `CheckAllowedOrigins` reduces URL-like values to their `host` component and accepts on host match alone. This makes exact origin policies impossible to express: scheme and port differences are silently ignored.</p>
<p>### Details
`CheckAllowedOrigins` stores each configured allowed origin as:</p>
<p>```php
parse_url($allowedOrigin)['host'] ?? $allowedOrigin
```</p>
<p>and later reduces the received `clientDataJSON.origin` the same way:</p>
<p>```php
parse_url($C-&gt;origin)['host'] ?? $C-&gt;origin
```</p>
<p>If the reduced value matches, the method returns early. As a result, for the normal `allowed_origins` path, the later HTTPS check is not reached.</p>
<p>This differs from [WebAuthn Level 2](https://www.w3.org/TR/webauthn-2/), which requires verifying that `C.origin` matches the RP's origin (scheme + host + port), separately from verifying that `authData.rpIdHash` matches the expected RP ID.</p>
<p>**Affected code:**
- [CheckAllowedOrigins.php](https://github.com/web-auth/webauthn-framework/blob/d58906e/src/webauthn/src/CeremonyStep/CheckAllowedOrigins.php)</p>
<p>**Spec references:**
- [§7.1 Registering a New Credential](https://www.w3.org/TR/webauthn-2/#sctn-registering-a-new-credential)
- [§7.2 Verifying an Authentication Assertion](https://www.w3.org/TR/webauthn-2/#sctn-verifying-assertion)
- [CollectedClientData.origin](https://www.w3.org/TR/webauthn-2/#dom-collectedclientdata-origin)</p>
<p>### PoC
Configuration:</p>
<p>```yaml
webauthn:
  allowed_origins:
    - https://login.exam…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-f7pm-6hr8-7ggm"/>
  </entry>
</feed>
