<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 05:40:06 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-275302</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-275302</link>
      <description>EUVD-2026-275302</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-275302</guid>
    </item>
    <item>
      <title>fkie_cve-2026-30964</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-30964</link>
      <description>&lt;p&gt;web-auth/webauthn-lib is an open source set of PHP libraries and a Symfony bundle to allow developers to integrate that authentication mechanism into their web applications. Prior to 5.2.4, when allowed_origins is configured, CheckAllowedOrigins reduces URL-like values to their host component and accepts on host match alone. This makes exact origin policies impossible to express: scheme and port differences are silently ignored. This vulnerability is fixed in 5.2.4.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;web-auth/webauthn-lib is an open source set of PHP libraries and a Symfony bundle to allow developers to integrate that authentication mechanism into their web applications. Prior to 5.2.4, when allowed_origins is configured, CheckAllowedOrigins reduces URL-like values to their host component and accepts on host match alone. This makes exact origin policies impossible to express: scheme and port differences are silently ignored. This vulnerability is fixed in 5.2.4.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-30964</guid>
    </item>
    <item>
      <title>GHSA-f7pm-6hr8-7ggm — Webauthn Framework: allowed_origins collapses URL-like origins to host-only values, bypassing exact origin validation</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-f7pm-6hr8-7ggm</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: web-auth/webauthn-framework, Packagist: web-auth/webauthn-lib, Packagist: web-auth/webauthn-symfony-bundle&lt;/p&gt;
&lt;p&gt;### Summary
When `allowed_origins` is configured, `CheckAllowedOrigins` reduces URL-like values to their `host` component and accepts on host match alone. This makes exact origin policies impossible to express: scheme and port differences are silently ignored.&lt;/p&gt;
&lt;p&gt;### Details
`CheckAllowedOrigins` stores each configured allowed origin as:&lt;/p&gt;
&lt;p&gt;```php
parse_url($allowedOrigin)[&amp;#39;host&amp;#39;] ?? $allowedOrigin
```&lt;/p&gt;
&lt;p&gt;and later reduces the received `clientDataJSON.origin` the same way:&lt;/p&gt;
&lt;p&gt;```php
parse_url($C-&amp;gt;origin)[&amp;#39;host&amp;#39;] ?? $C-&amp;gt;origin
```&lt;/p&gt;
&lt;p&gt;If the reduced value matches, the method returns early. As a result, for the normal `allowed_origins` path, the later HTTPS check is not reached.&lt;/p&gt;
&lt;p&gt;This differs from [WebAuthn Level 2](https://www.w3.org/TR/webauthn-2/), which requires verifying that `C.origin` matches the RP&amp;#39;s origin (scheme + host + port), separately from verifying that `authData.rpIdHash` matches the expected RP ID.&lt;/p&gt;
&lt;p&gt;**Affected code:**
- [CheckAllowedOrigins.php](https://github.com/web-auth/webauthn-framework/blob/d58906e/src/webauthn/src/CeremonyStep/CheckAllowedOrigins.php)&lt;/p&gt;
&lt;p&gt;**Spec references:**
- [§7.1 Registering a New Credential](https://www.w3.org/TR/webauthn-2/#sctn-registering-a-new-credential)
- [§7.2 Verifying an Authentication Assertion](https://www.w3.org/TR/webauthn-2/#sctn-verifying-assertion)
- [CollectedClientData.origin](https://www.w3.org/TR/webauthn-2/#dom-collectedclientdata-origin)&lt;/p&gt;
&lt;p&gt;### PoC
Configuration:&lt;/p&gt;
&lt;p&gt;```yaml
webauthn:
  allowed_origins:
    - https://login.exam…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: web-auth/webauthn-framework, Packagist: web-auth/webauthn-lib, Packagist: web-auth/webauthn-symfony-bundle&lt;/p&gt;
&lt;p&gt;### Summary
When `allowed_origins` is configured, `CheckAllowedOrigins` reduces URL-like values to their `host` component and accepts on host match alone. This makes exact origin policies impossible to express: scheme and port differences are silently ignored.&lt;/p&gt;
&lt;p&gt;### Details
`CheckAllowedOrigins` stores each configured allowed origin as:&lt;/p&gt;
&lt;p&gt;```php
parse_url($allowedOrigin)[&amp;#39;host&amp;#39;] ?? $allowedOrigin
```&lt;/p&gt;
&lt;p&gt;and later reduces the received `clientDataJSON.origin` the same way:&lt;/p&gt;
&lt;p&gt;```php
parse_url($C-&amp;gt;origin)[&amp;#39;host&amp;#39;] ?? $C-&amp;gt;origin
```&lt;/p&gt;
&lt;p&gt;If the reduced value matches, the method returns early. As a result, for the normal `allowed_origins` path, the later HTTPS check is not reached.&lt;/p&gt;
&lt;p&gt;This differs from [WebAuthn Level 2](https://www.w3.org/TR/webauthn-2/), which requires verifying that `C.origin` matches the RP&amp;#39;s origin (scheme + host + port), separately from verifying that `authData.rpIdHash` matches the expected RP ID.&lt;/p&gt;
&lt;p&gt;**Affected code:**
- [CheckAllowedOrigins.php](https://github.com/web-auth/webauthn-framework/blob/d58906e/src/webauthn/src/CeremonyStep/CheckAllowedOrigins.php)&lt;/p&gt;
&lt;p&gt;**Spec references:**
- [§7.1 Registering a New Credential](https://www.w3.org/TR/webauthn-2/#sctn-registering-a-new-credential)
- [§7.2 Verifying an Authentication Assertion](https://www.w3.org/TR/webauthn-2/#sctn-verifying-assertion)
- [CollectedClientData.origin](https://www.w3.org/TR/webauthn-2/#dom-collectedclientdata-origin)&lt;/p&gt;
&lt;p&gt;### PoC
Configuration:&lt;/p&gt;
&lt;p&gt;```yaml
webauthn:
  allowed_origins:
    - https://login.exam…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-f7pm-6hr8-7ggm</guid>
    </item>
  </channel>
</rss>
