webauthn-authenticator-rs
Activity
- Latest release
- 4mo ago
- Total releases
- 28
- Cadence
- ~41 days
- Last 12 months
- 5
Details
- License
- MPL-2.0
- First release
- Oct 24, 2020
| Version | Released | |
|---|---|---|
0.5.5
unknown
|
0.5.5
unknown
Dependencies (41)
+ 33 more |
|
0.6.1-dev
unknown
|
0.6.1-dev
unknown
Dependencies (40)
+ 32 more |
|
0.6.0-dev
unknown
1 CVE
GHSA-22w3-693w-x895
May 06, 2026
webauthn-rs-core/webauthn-authenticator-rs: Origin validation mismatch possible when subdomains are allowed
Low
Network
High
None
Summary
This check is flawed, and could allow requests from an attacker-controlled domain such as
These issues are a violation of WebAuthn Level 3 §13.4.9, §5.1.3 Step 8 and §5.1.4.1 Step 7. Details
Origin | RP ID | Expected result | Result with incorrect FixWhen
Regression tests for this bug have been added to both libraries. ImpactWith a both a non-conforming client implementation and vulnerable version of However, conforming client implementations (ie: all web browsers) will refuse to process WebAuthn requests for an RP ID that does not match the In the scenario above with conforming client-side checks, this would force the attacker to change the request's RP ID to SeverityPer WebAuthn §13.4.9:
Unfortunately, the chain needed to exploit this bug makes it difficult to classify with the CVSS framework. Kanidm came up with anywhere between "low" and "high" depending on the approach, and GitHub only provides one CVSS field for everything. An attacker could easily bypass a correctly-implemented server-side However, Due to the complex preconditions and non-default configuration required to execute a successful attack, and that it is not exploitable in popular web browsers, Kanidm considers this a low severity issue. Affected versions
0.6.0-dev
Fixed in
0.5.5
0.6.1-dev
References Updated Sep 10, 2026 · Source: OSV.dev |
0.6.0-dev
unknown
Dependencies (41)
+ 33 more |
|
0.5.4
unknown
1 CVE
GHSA-22w3-693w-x895
May 06, 2026
webauthn-rs-core/webauthn-authenticator-rs: Origin validation mismatch possible when subdomains are allowed
Low
Network
High
None
Summary
This check is flawed, and could allow requests from an attacker-controlled domain such as
These issues are a violation of WebAuthn Level 3 §13.4.9, §5.1.3 Step 8 and §5.1.4.1 Step 7. Details
Origin | RP ID | Expected result | Result with incorrect FixWhen
Regression tests for this bug have been added to both libraries. ImpactWith a both a non-conforming client implementation and vulnerable version of However, conforming client implementations (ie: all web browsers) will refuse to process WebAuthn requests for an RP ID that does not match the In the scenario above with conforming client-side checks, this would force the attacker to change the request's RP ID to SeverityPer WebAuthn §13.4.9:
Unfortunately, the chain needed to exploit this bug makes it difficult to classify with the CVSS framework. Kanidm came up with anywhere between "low" and "high" depending on the approach, and GitHub only provides one CVSS field for everything. An attacker could easily bypass a correctly-implemented server-side However, Due to the complex preconditions and non-default configuration required to execute a successful attack, and that it is not exploitable in popular web browsers, Kanidm considers this a low severity issue. Affected versions
0.6.0-dev
Fixed in
0.5.5
0.6.1-dev
References Updated Sep 10, 2026 · Source: OSV.dev |
0.5.4
unknown
Dependencies (40)
+ 32 more |
|
0.5.3
unknown
1 CVE
GHSA-22w3-693w-x895
May 06, 2026
webauthn-rs-core/webauthn-authenticator-rs: Origin validation mismatch possible when subdomains are allowed
Low
Network
High
None
Summary
This check is flawed, and could allow requests from an attacker-controlled domain such as
These issues are a violation of WebAuthn Level 3 §13.4.9, §5.1.3 Step 8 and §5.1.4.1 Step 7. Details
Origin | RP ID | Expected result | Result with incorrect FixWhen
Regression tests for this bug have been added to both libraries. ImpactWith a both a non-conforming client implementation and vulnerable version of However, conforming client implementations (ie: all web browsers) will refuse to process WebAuthn requests for an RP ID that does not match the In the scenario above with conforming client-side checks, this would force the attacker to change the request's RP ID to SeverityPer WebAuthn §13.4.9:
Unfortunately, the chain needed to exploit this bug makes it difficult to classify with the CVSS framework. Kanidm came up with anywhere between "low" and "high" depending on the approach, and GitHub only provides one CVSS field for everything. An attacker could easily bypass a correctly-implemented server-side However, Due to the complex preconditions and non-default configuration required to execute a successful attack, and that it is not exploitable in popular web browsers, Kanidm considers this a low severity issue. Affected versions
0.6.0-dev
Fixed in
0.5.5
0.6.1-dev
References Updated Sep 10, 2026 · Source: OSV.dev |
0.5.3
unknown
Dependencies (40)
+ 32 more |
|
0.5.2
unknown
1 CVE
GHSA-22w3-693w-x895
May 06, 2026
webauthn-rs-core/webauthn-authenticator-rs: Origin validation mismatch possible when subdomains are allowed
Low
Network
High
None
Summary
This check is flawed, and could allow requests from an attacker-controlled domain such as
These issues are a violation of WebAuthn Level 3 §13.4.9, §5.1.3 Step 8 and §5.1.4.1 Step 7. Details
Origin | RP ID | Expected result | Result with incorrect FixWhen
Regression tests for this bug have been added to both libraries. ImpactWith a both a non-conforming client implementation and vulnerable version of However, conforming client implementations (ie: all web browsers) will refuse to process WebAuthn requests for an RP ID that does not match the In the scenario above with conforming client-side checks, this would force the attacker to change the request's RP ID to SeverityPer WebAuthn §13.4.9:
Unfortunately, the chain needed to exploit this bug makes it difficult to classify with the CVSS framework. Kanidm came up with anywhere between "low" and "high" depending on the approach, and GitHub only provides one CVSS field for everything. An attacker could easily bypass a correctly-implemented server-side However, Due to the complex preconditions and non-default configuration required to execute a successful attack, and that it is not exploitable in popular web browsers, Kanidm considers this a low severity issue. Affected versions
0.6.0-dev
Fixed in
0.5.5
0.6.1-dev
References Updated Sep 10, 2026 · Source: OSV.dev |
0.5.2
unknown
Dependencies (40)
+ 32 more |
|
0.5.1
unknown
1 CVE
GHSA-22w3-693w-x895
May 06, 2026
webauthn-rs-core/webauthn-authenticator-rs: Origin validation mismatch possible when subdomains are allowed
Low
Network
High
None
Summary
This check is flawed, and could allow requests from an attacker-controlled domain such as
These issues are a violation of WebAuthn Level 3 §13.4.9, §5.1.3 Step 8 and §5.1.4.1 Step 7. Details
Origin | RP ID | Expected result | Result with incorrect FixWhen
Regression tests for this bug have been added to both libraries. ImpactWith a both a non-conforming client implementation and vulnerable version of However, conforming client implementations (ie: all web browsers) will refuse to process WebAuthn requests for an RP ID that does not match the In the scenario above with conforming client-side checks, this would force the attacker to change the request's RP ID to SeverityPer WebAuthn §13.4.9:
Unfortunately, the chain needed to exploit this bug makes it difficult to classify with the CVSS framework. Kanidm came up with anywhere between "low" and "high" depending on the approach, and GitHub only provides one CVSS field for everything. An attacker could easily bypass a correctly-implemented server-side However, Due to the complex preconditions and non-default configuration required to execute a successful attack, and that it is not exploitable in popular web browsers, Kanidm considers this a low severity issue. Affected versions
0.6.0-dev
Fixed in
0.5.5
0.6.1-dev
References Updated Sep 10, 2026 · Source: OSV.dev |
0.5.1
unknown
Dependencies (39)
+ 31 more |
|
0.5.0
unknown
1 CVE
GHSA-22w3-693w-x895
May 06, 2026
webauthn-rs-core/webauthn-authenticator-rs: Origin validation mismatch possible when subdomains are allowed
Low
Network
High
None
Summary
This check is flawed, and could allow requests from an attacker-controlled domain such as
These issues are a violation of WebAuthn Level 3 §13.4.9, §5.1.3 Step 8 and §5.1.4.1 Step 7. Details
Origin | RP ID | Expected result | Result with incorrect FixWhen
Regression tests for this bug have been added to both libraries. ImpactWith a both a non-conforming client implementation and vulnerable version of However, conforming client implementations (ie: all web browsers) will refuse to process WebAuthn requests for an RP ID that does not match the In the scenario above with conforming client-side checks, this would force the attacker to change the request's RP ID to SeverityPer WebAuthn §13.4.9:
Unfortunately, the chain needed to exploit this bug makes it difficult to classify with the CVSS framework. Kanidm came up with anywhere between "low" and "high" depending on the approach, and GitHub only provides one CVSS field for everything. An attacker could easily bypass a correctly-implemented server-side However, Due to the complex preconditions and non-default configuration required to execute a successful attack, and that it is not exploitable in popular web browsers, Kanidm considers this a low severity issue. Affected versions
0.6.0-dev
Fixed in
0.5.5
0.6.1-dev
References Updated Sep 10, 2026 · Source: OSV.dev |
0.5.0
unknown
Dependencies (39)
+ 31 more |
|
0.5.0-dev
unknown
1 CVE
GHSA-22w3-693w-x895
May 06, 2026
webauthn-rs-core/webauthn-authenticator-rs: Origin validation mismatch possible when subdomains are allowed
Low
Network
High
None
Summary
This check is flawed, and could allow requests from an attacker-controlled domain such as
These issues are a violation of WebAuthn Level 3 §13.4.9, §5.1.3 Step 8 and §5.1.4.1 Step 7. Details
Origin | RP ID | Expected result | Result with incorrect FixWhen
Regression tests for this bug have been added to both libraries. ImpactWith a both a non-conforming client implementation and vulnerable version of However, conforming client implementations (ie: all web browsers) will refuse to process WebAuthn requests for an RP ID that does not match the In the scenario above with conforming client-side checks, this would force the attacker to change the request's RP ID to SeverityPer WebAuthn §13.4.9:
Unfortunately, the chain needed to exploit this bug makes it difficult to classify with the CVSS framework. Kanidm came up with anywhere between "low" and "high" depending on the approach, and GitHub only provides one CVSS field for everything. An attacker could easily bypass a correctly-implemented server-side However, Due to the complex preconditions and non-default configuration required to execute a successful attack, and that it is not exploitable in popular web browsers, Kanidm considers this a low severity issue. Affected versions
0.6.0-dev
Fixed in
0.5.5
0.6.1-dev
References Updated Sep 10, 2026 · Source: OSV.dev |
0.5.0-dev
unknown
Dependencies (38)
+ 30 more |
|
0.4.9
unknown
1 CVE
GHSA-22w3-693w-x895
May 06, 2026
webauthn-rs-core/webauthn-authenticator-rs: Origin validation mismatch possible when subdomains are allowed
Low
Network
High
None
Summary
This check is flawed, and could allow requests from an attacker-controlled domain such as
These issues are a violation of WebAuthn Level 3 §13.4.9, §5.1.3 Step 8 and §5.1.4.1 Step 7. Details
Origin | RP ID | Expected result | Result with incorrect FixWhen
Regression tests for this bug have been added to both libraries. ImpactWith a both a non-conforming client implementation and vulnerable version of However, conforming client implementations (ie: all web browsers) will refuse to process WebAuthn requests for an RP ID that does not match the In the scenario above with conforming client-side checks, this would force the attacker to change the request's RP ID to SeverityPer WebAuthn §13.4.9:
Unfortunately, the chain needed to exploit this bug makes it difficult to classify with the CVSS framework. Kanidm came up with anywhere between "low" and "high" depending on the approach, and GitHub only provides one CVSS field for everything. An attacker could easily bypass a correctly-implemented server-side However, Due to the complex preconditions and non-default configuration required to execute a successful attack, and that it is not exploitable in popular web browsers, Kanidm considers this a low severity issue. Affected versions
0.6.0-dev
Fixed in
0.5.5
0.6.1-dev
References Updated Sep 10, 2026 · Source: OSV.dev |
0.4.9
unknown
Dependencies (17)
+ 9 more |
|
0.4.8
unknown
1 CVE
GHSA-22w3-693w-x895
May 06, 2026
webauthn-rs-core/webauthn-authenticator-rs: Origin validation mismatch possible when subdomains are allowed
Low
Network
High
None
Summary
This check is flawed, and could allow requests from an attacker-controlled domain such as
These issues are a violation of WebAuthn Level 3 §13.4.9, §5.1.3 Step 8 and §5.1.4.1 Step 7. Details
Origin | RP ID | Expected result | Result with incorrect FixWhen
Regression tests for this bug have been added to both libraries. ImpactWith a both a non-conforming client implementation and vulnerable version of However, conforming client implementations (ie: all web browsers) will refuse to process WebAuthn requests for an RP ID that does not match the In the scenario above with conforming client-side checks, this would force the attacker to change the request's RP ID to SeverityPer WebAuthn §13.4.9:
Unfortunately, the chain needed to exploit this bug makes it difficult to classify with the CVSS framework. Kanidm came up with anywhere between "low" and "high" depending on the approach, and GitHub only provides one CVSS field for everything. An attacker could easily bypass a correctly-implemented server-side However, Due to the complex preconditions and non-default configuration required to execute a successful attack, and that it is not exploitable in popular web browsers, Kanidm considers this a low severity issue. Affected versions
0.6.0-dev
Fixed in
0.5.5
0.6.1-dev
References Updated Sep 10, 2026 · Source: OSV.dev |
0.4.8
unknown
Dependencies (17)
+ 9 more |
|
0.4.7
unknown
1 CVE
GHSA-22w3-693w-x895
May 06, 2026
webauthn-rs-core/webauthn-authenticator-rs: Origin validation mismatch possible when subdomains are allowed
Low
Network
High
None
Summary
This check is flawed, and could allow requests from an attacker-controlled domain such as
These issues are a violation of WebAuthn Level 3 §13.4.9, §5.1.3 Step 8 and §5.1.4.1 Step 7. Details
Origin | RP ID | Expected result | Result with incorrect FixWhen
Regression tests for this bug have been added to both libraries. ImpactWith a both a non-conforming client implementation and vulnerable version of However, conforming client implementations (ie: all web browsers) will refuse to process WebAuthn requests for an RP ID that does not match the In the scenario above with conforming client-side checks, this would force the attacker to change the request's RP ID to SeverityPer WebAuthn §13.4.9:
Unfortunately, the chain needed to exploit this bug makes it difficult to classify with the CVSS framework. Kanidm came up with anywhere between "low" and "high" depending on the approach, and GitHub only provides one CVSS field for everything. An attacker could easily bypass a correctly-implemented server-side However, Due to the complex preconditions and non-default configuration required to execute a successful attack, and that it is not exploitable in popular web browsers, Kanidm considers this a low severity issue. Affected versions
0.6.0-dev
Fixed in
0.5.5
0.6.1-dev
References Updated Sep 10, 2026 · Source: OSV.dev |
0.4.7
unknown
Dependencies (15)
+ 7 more |
|
0.4.5
unknown
1 CVE
GHSA-22w3-693w-x895
May 06, 2026
webauthn-rs-core/webauthn-authenticator-rs: Origin validation mismatch possible when subdomains are allowed
Low
Network
High
None
Summary
This check is flawed, and could allow requests from an attacker-controlled domain such as
These issues are a violation of WebAuthn Level 3 §13.4.9, §5.1.3 Step 8 and §5.1.4.1 Step 7. Details
Origin | RP ID | Expected result | Result with incorrect FixWhen
Regression tests for this bug have been added to both libraries. ImpactWith a both a non-conforming client implementation and vulnerable version of However, conforming client implementations (ie: all web browsers) will refuse to process WebAuthn requests for an RP ID that does not match the In the scenario above with conforming client-side checks, this would force the attacker to change the request's RP ID to SeverityPer WebAuthn §13.4.9:
Unfortunately, the chain needed to exploit this bug makes it difficult to classify with the CVSS framework. Kanidm came up with anywhere between "low" and "high" depending on the approach, and GitHub only provides one CVSS field for everything. An attacker could easily bypass a correctly-implemented server-side However, Due to the complex preconditions and non-default configuration required to execute a successful attack, and that it is not exploitable in popular web browsers, Kanidm considers this a low severity issue. Affected versions
0.6.0-dev
Fixed in
0.5.5
0.6.1-dev
References Updated Sep 10, 2026 · Source: OSV.dev |
0.4.5
unknown
Dependencies (14)
+ 6 more |
|
0.3.2
unknown
1 CVE
GHSA-22w3-693w-x895
May 06, 2026
webauthn-rs-core/webauthn-authenticator-rs: Origin validation mismatch possible when subdomains are allowed
Low
Network
High
None
Summary
This check is flawed, and could allow requests from an attacker-controlled domain such as
These issues are a violation of WebAuthn Level 3 §13.4.9, §5.1.3 Step 8 and §5.1.4.1 Step 7. Details
Origin | RP ID | Expected result | Result with incorrect FixWhen
Regression tests for this bug have been added to both libraries. ImpactWith a both a non-conforming client implementation and vulnerable version of However, conforming client implementations (ie: all web browsers) will refuse to process WebAuthn requests for an RP ID that does not match the In the scenario above with conforming client-side checks, this would force the attacker to change the request's RP ID to SeverityPer WebAuthn §13.4.9:
Unfortunately, the chain needed to exploit this bug makes it difficult to classify with the CVSS framework. Kanidm came up with anywhere between "low" and "high" depending on the approach, and GitHub only provides one CVSS field for everything. An attacker could easily bypass a correctly-implemented server-side However, Due to the complex preconditions and non-default configuration required to execute a successful attack, and that it is not exploitable in popular web browsers, Kanidm considers this a low severity issue. Affected versions
0.6.0-dev
Fixed in
0.5.5
0.6.1-dev
References Updated Sep 10, 2026 · Source: OSV.dev |
0.3.2
unknown
Dependencies (12)
+ 4 more |
|
0.3.1
unknown
1 CVE
GHSA-22w3-693w-x895
May 06, 2026
webauthn-rs-core/webauthn-authenticator-rs: Origin validation mismatch possible when subdomains are allowed
Low
Network
High
None
Summary
This check is flawed, and could allow requests from an attacker-controlled domain such as
These issues are a violation of WebAuthn Level 3 §13.4.9, §5.1.3 Step 8 and §5.1.4.1 Step 7. Details
Origin | RP ID | Expected result | Result with incorrect FixWhen
Regression tests for this bug have been added to both libraries. ImpactWith a both a non-conforming client implementation and vulnerable version of However, conforming client implementations (ie: all web browsers) will refuse to process WebAuthn requests for an RP ID that does not match the In the scenario above with conforming client-side checks, this would force the attacker to change the request's RP ID to SeverityPer WebAuthn §13.4.9:
Unfortunately, the chain needed to exploit this bug makes it difficult to classify with the CVSS framework. Kanidm came up with anywhere between "low" and "high" depending on the approach, and GitHub only provides one CVSS field for everything. An attacker could easily bypass a correctly-implemented server-side However, Due to the complex preconditions and non-default configuration required to execute a successful attack, and that it is not exploitable in popular web browsers, Kanidm considers this a low severity issue. Affected versions
0.6.0-dev
Fixed in
0.5.5
0.6.1-dev
References Updated Sep 10, 2026 · Source: OSV.dev |
0.3.1
unknown
Dependencies (10)
+ 2 more |
|
0.3.0
unknown
1 CVE
GHSA-22w3-693w-x895
May 06, 2026
webauthn-rs-core/webauthn-authenticator-rs: Origin validation mismatch possible when subdomains are allowed
Low
Network
High
None
Summary
This check is flawed, and could allow requests from an attacker-controlled domain such as
These issues are a violation of WebAuthn Level 3 §13.4.9, §5.1.3 Step 8 and §5.1.4.1 Step 7. Details
Origin | RP ID | Expected result | Result with incorrect FixWhen
Regression tests for this bug have been added to both libraries. ImpactWith a both a non-conforming client implementation and vulnerable version of However, conforming client implementations (ie: all web browsers) will refuse to process WebAuthn requests for an RP ID that does not match the In the scenario above with conforming client-side checks, this would force the attacker to change the request's RP ID to SeverityPer WebAuthn §13.4.9:
Unfortunately, the chain needed to exploit this bug makes it difficult to classify with the CVSS framework. Kanidm came up with anywhere between "low" and "high" depending on the approach, and GitHub only provides one CVSS field for everything. An attacker could easily bypass a correctly-implemented server-side However, Due to the complex preconditions and non-default configuration required to execute a successful attack, and that it is not exploitable in popular web browsers, Kanidm considers this a low severity issue. Affected versions
0.6.0-dev
Fixed in
0.5.5
0.6.1-dev
References Updated Sep 10, 2026 · Source: OSV.dev |
0.3.0
unknown
Dependencies (10)
+ 2 more |
|
0.3.0-alpha.12
unknown
1 CVE
GHSA-22w3-693w-x895
May 06, 2026
webauthn-rs-core/webauthn-authenticator-rs: Origin validation mismatch possible when subdomains are allowed
Low
Network
High
None
Summary
This check is flawed, and could allow requests from an attacker-controlled domain such as
These issues are a violation of WebAuthn Level 3 §13.4.9, §5.1.3 Step 8 and §5.1.4.1 Step 7. Details
Origin | RP ID | Expected result | Result with incorrect FixWhen
Regression tests for this bug have been added to both libraries. ImpactWith a both a non-conforming client implementation and vulnerable version of However, conforming client implementations (ie: all web browsers) will refuse to process WebAuthn requests for an RP ID that does not match the In the scenario above with conforming client-side checks, this would force the attacker to change the request's RP ID to SeverityPer WebAuthn §13.4.9:
Unfortunately, the chain needed to exploit this bug makes it difficult to classify with the CVSS framework. Kanidm came up with anywhere between "low" and "high" depending on the approach, and GitHub only provides one CVSS field for everything. An attacker could easily bypass a correctly-implemented server-side However, Due to the complex preconditions and non-default configuration required to execute a successful attack, and that it is not exploitable in popular web browsers, Kanidm considers this a low severity issue. Affected versions
0.6.0-dev
Fixed in
0.5.5
0.6.1-dev
References Updated Sep 10, 2026 · Source: OSV.dev |
0.3.0-alpha.12
unknown
Dependencies (10)
+ 2 more |
|
0.3.0-alpha.11
unknown
1 CVE
GHSA-22w3-693w-x895
May 06, 2026
webauthn-rs-core/webauthn-authenticator-rs: Origin validation mismatch possible when subdomains are allowed
Low
Network
High
None
Summary
This check is flawed, and could allow requests from an attacker-controlled domain such as
These issues are a violation of WebAuthn Level 3 §13.4.9, §5.1.3 Step 8 and §5.1.4.1 Step 7. Details
Origin | RP ID | Expected result | Result with incorrect FixWhen
Regression tests for this bug have been added to both libraries. ImpactWith a both a non-conforming client implementation and vulnerable version of However, conforming client implementations (ie: all web browsers) will refuse to process WebAuthn requests for an RP ID that does not match the In the scenario above with conforming client-side checks, this would force the attacker to change the request's RP ID to SeverityPer WebAuthn §13.4.9:
Unfortunately, the chain needed to exploit this bug makes it difficult to classify with the CVSS framework. Kanidm came up with anywhere between "low" and "high" depending on the approach, and GitHub only provides one CVSS field for everything. An attacker could easily bypass a correctly-implemented server-side However, Due to the complex preconditions and non-default configuration required to execute a successful attack, and that it is not exploitable in popular web browsers, Kanidm considers this a low severity issue. Affected versions
0.6.0-dev
Fixed in
0.5.5
0.6.1-dev
References Updated Sep 10, 2026 · Source: OSV.dev |
0.3.0-alpha.11
unknown
Dependencies (10)
+ 2 more |
|
0.3.0-alpha.10
unknown
1 CVE
GHSA-22w3-693w-x895
May 06, 2026
webauthn-rs-core/webauthn-authenticator-rs: Origin validation mismatch possible when subdomains are allowed
Low
Network
High
None
Summary
This check is flawed, and could allow requests from an attacker-controlled domain such as
These issues are a violation of WebAuthn Level 3 §13.4.9, §5.1.3 Step 8 and §5.1.4.1 Step 7. Details
Origin | RP ID | Expected result | Result with incorrect FixWhen
Regression tests for this bug have been added to both libraries. ImpactWith a both a non-conforming client implementation and vulnerable version of However, conforming client implementations (ie: all web browsers) will refuse to process WebAuthn requests for an RP ID that does not match the In the scenario above with conforming client-side checks, this would force the attacker to change the request's RP ID to SeverityPer WebAuthn §13.4.9:
Unfortunately, the chain needed to exploit this bug makes it difficult to classify with the CVSS framework. Kanidm came up with anywhere between "low" and "high" depending on the approach, and GitHub only provides one CVSS field for everything. An attacker could easily bypass a correctly-implemented server-side However, Due to the complex preconditions and non-default configuration required to execute a successful attack, and that it is not exploitable in popular web browsers, Kanidm considers this a low severity issue. Affected versions
0.6.0-dev
Fixed in
0.5.5
0.6.1-dev
References Updated Sep 10, 2026 · Source: OSV.dev |
0.3.0-alpha.10
unknown
Dependencies (10)
+ 2 more |
|
0.3.0-alpha.9
unknown
1 CVE
GHSA-22w3-693w-x895
May 06, 2026
webauthn-rs-core/webauthn-authenticator-rs: Origin validation mismatch possible when subdomains are allowed
Low
Network
High
None
Summary
This check is flawed, and could allow requests from an attacker-controlled domain such as
These issues are a violation of WebAuthn Level 3 §13.4.9, §5.1.3 Step 8 and §5.1.4.1 Step 7. Details
Origin | RP ID | Expected result | Result with incorrect FixWhen
Regression tests for this bug have been added to both libraries. ImpactWith a both a non-conforming client implementation and vulnerable version of However, conforming client implementations (ie: all web browsers) will refuse to process WebAuthn requests for an RP ID that does not match the In the scenario above with conforming client-side checks, this would force the attacker to change the request's RP ID to SeverityPer WebAuthn §13.4.9:
Unfortunately, the chain needed to exploit this bug makes it difficult to classify with the CVSS framework. Kanidm came up with anywhere between "low" and "high" depending on the approach, and GitHub only provides one CVSS field for everything. An attacker could easily bypass a correctly-implemented server-side However, Due to the complex preconditions and non-default configuration required to execute a successful attack, and that it is not exploitable in popular web browsers, Kanidm considers this a low severity issue. Affected versions
0.6.0-dev
Fixed in
0.5.5
0.6.1-dev
References Updated Sep 10, 2026 · Source: OSV.dev |
0.3.0-alpha.9
unknown
Dependencies (10)
+ 2 more |
|
0.3.0-alpha.8
unknown
1 CVE
GHSA-22w3-693w-x895
May 06, 2026
webauthn-rs-core/webauthn-authenticator-rs: Origin validation mismatch possible when subdomains are allowed
Low
Network
High
None
Summary
This check is flawed, and could allow requests from an attacker-controlled domain such as
These issues are a violation of WebAuthn Level 3 §13.4.9, §5.1.3 Step 8 and §5.1.4.1 Step 7. Details
Origin | RP ID | Expected result | Result with incorrect FixWhen
Regression tests for this bug have been added to both libraries. ImpactWith a both a non-conforming client implementation and vulnerable version of However, conforming client implementations (ie: all web browsers) will refuse to process WebAuthn requests for an RP ID that does not match the In the scenario above with conforming client-side checks, this would force the attacker to change the request's RP ID to SeverityPer WebAuthn §13.4.9:
Unfortunately, the chain needed to exploit this bug makes it difficult to classify with the CVSS framework. Kanidm came up with anywhere between "low" and "high" depending on the approach, and GitHub only provides one CVSS field for everything. An attacker could easily bypass a correctly-implemented server-side However, Due to the complex preconditions and non-default configuration required to execute a successful attack, and that it is not exploitable in popular web browsers, Kanidm considers this a low severity issue. Affected versions
0.6.0-dev
Fixed in
0.5.5
0.6.1-dev
References Updated Sep 10, 2026 · Source: OSV.dev |
0.3.0-alpha.8
unknown
Dependencies (10)
+ 2 more |
|
0.3.0-alpha.7
unknown
1 CVE
GHSA-22w3-693w-x895
May 06, 2026
webauthn-rs-core/webauthn-authenticator-rs: Origin validation mismatch possible when subdomains are allowed
Low
Network
High
None
Summary
This check is flawed, and could allow requests from an attacker-controlled domain such as
These issues are a violation of WebAuthn Level 3 §13.4.9, §5.1.3 Step 8 and §5.1.4.1 Step 7. Details
Origin | RP ID | Expected result | Result with incorrect FixWhen
Regression tests for this bug have been added to both libraries. ImpactWith a both a non-conforming client implementation and vulnerable version of However, conforming client implementations (ie: all web browsers) will refuse to process WebAuthn requests for an RP ID that does not match the In the scenario above with conforming client-side checks, this would force the attacker to change the request's RP ID to SeverityPer WebAuthn §13.4.9:
Unfortunately, the chain needed to exploit this bug makes it difficult to classify with the CVSS framework. Kanidm came up with anywhere between "low" and "high" depending on the approach, and GitHub only provides one CVSS field for everything. An attacker could easily bypass a correctly-implemented server-side However, Due to the complex preconditions and non-default configuration required to execute a successful attack, and that it is not exploitable in popular web browsers, Kanidm considers this a low severity issue. Affected versions
0.6.0-dev
Fixed in
0.5.5
0.6.1-dev
References Updated Sep 10, 2026 · Source: OSV.dev |
0.3.0-alpha.7
unknown
Dependencies (10)
+ 2 more |
|
0.3.0-alpha.6
unknown
1 CVE
GHSA-22w3-693w-x895
May 06, 2026
webauthn-rs-core/webauthn-authenticator-rs: Origin validation mismatch possible when subdomains are allowed
Low
Network
High
None
Summary
This check is flawed, and could allow requests from an attacker-controlled domain such as
These issues are a violation of WebAuthn Level 3 §13.4.9, §5.1.3 Step 8 and §5.1.4.1 Step 7. Details
Origin | RP ID | Expected result | Result with incorrect FixWhen
Regression tests for this bug have been added to both libraries. ImpactWith a both a non-conforming client implementation and vulnerable version of However, conforming client implementations (ie: all web browsers) will refuse to process WebAuthn requests for an RP ID that does not match the In the scenario above with conforming client-side checks, this would force the attacker to change the request's RP ID to SeverityPer WebAuthn §13.4.9:
Unfortunately, the chain needed to exploit this bug makes it difficult to classify with the CVSS framework. Kanidm came up with anywhere between "low" and "high" depending on the approach, and GitHub only provides one CVSS field for everything. An attacker could easily bypass a correctly-implemented server-side However, Due to the complex preconditions and non-default configuration required to execute a successful attack, and that it is not exploitable in popular web browsers, Kanidm considers this a low severity issue. Affected versions
0.6.0-dev
Fixed in
0.5.5
0.6.1-dev
References Updated Sep 10, 2026 · Source: OSV.dev |
0.3.0-alpha.6
unknown
Dependencies (10)
+ 2 more |
|
0.3.0-alpha.5
unknown
1 CVE
GHSA-22w3-693w-x895
May 06, 2026
webauthn-rs-core/webauthn-authenticator-rs: Origin validation mismatch possible when subdomains are allowed
Low
Network
High
None
Summary
This check is flawed, and could allow requests from an attacker-controlled domain such as
These issues are a violation of WebAuthn Level 3 §13.4.9, §5.1.3 Step 8 and §5.1.4.1 Step 7. Details
Origin | RP ID | Expected result | Result with incorrect FixWhen
Regression tests for this bug have been added to both libraries. ImpactWith a both a non-conforming client implementation and vulnerable version of However, conforming client implementations (ie: all web browsers) will refuse to process WebAuthn requests for an RP ID that does not match the In the scenario above with conforming client-side checks, this would force the attacker to change the request's RP ID to SeverityPer WebAuthn §13.4.9:
Unfortunately, the chain needed to exploit this bug makes it difficult to classify with the CVSS framework. Kanidm came up with anywhere between "low" and "high" depending on the approach, and GitHub only provides one CVSS field for everything. An attacker could easily bypass a correctly-implemented server-side However, Due to the complex preconditions and non-default configuration required to execute a successful attack, and that it is not exploitable in popular web browsers, Kanidm considers this a low severity issue. Affected versions
0.6.0-dev
Fixed in
0.5.5
0.6.1-dev
References Updated Sep 10, 2026 · Source: OSV.dev |
0.3.0-alpha.5
unknown
Dependencies (10)
+ 2 more |
|
0.3.0-alpha.2
unknown
1 CVE
GHSA-22w3-693w-x895
May 06, 2026
webauthn-rs-core/webauthn-authenticator-rs: Origin validation mismatch possible when subdomains are allowed
Low
Network
High
None
Summary
This check is flawed, and could allow requests from an attacker-controlled domain such as
These issues are a violation of WebAuthn Level 3 §13.4.9, §5.1.3 Step 8 and §5.1.4.1 Step 7. Details
Origin | RP ID | Expected result | Result with incorrect FixWhen
Regression tests for this bug have been added to both libraries. ImpactWith a both a non-conforming client implementation and vulnerable version of However, conforming client implementations (ie: all web browsers) will refuse to process WebAuthn requests for an RP ID that does not match the In the scenario above with conforming client-side checks, this would force the attacker to change the request's RP ID to SeverityPer WebAuthn §13.4.9:
Unfortunately, the chain needed to exploit this bug makes it difficult to classify with the CVSS framework. Kanidm came up with anywhere between "low" and "high" depending on the approach, and GitHub only provides one CVSS field for everything. An attacker could easily bypass a correctly-implemented server-side However, Due to the complex preconditions and non-default configuration required to execute a successful attack, and that it is not exploitable in popular web browsers, Kanidm considers this a low severity issue. Affected versions
0.6.0-dev
Fixed in
0.5.5
0.6.1-dev
References Updated Sep 10, 2026 · Source: OSV.dev |
0.3.0-alpha.2
unknown
Dependencies (10)
+ 2 more |
|
0.3.0-alpha.1
unknown
1 CVE
GHSA-22w3-693w-x895
May 06, 2026
webauthn-rs-core/webauthn-authenticator-rs: Origin validation mismatch possible when subdomains are allowed
Low
Network
High
None
Summary
This check is flawed, and could allow requests from an attacker-controlled domain such as
These issues are a violation of WebAuthn Level 3 §13.4.9, §5.1.3 Step 8 and §5.1.4.1 Step 7. Details
Origin | RP ID | Expected result | Result with incorrect FixWhen
Regression tests for this bug have been added to both libraries. ImpactWith a both a non-conforming client implementation and vulnerable version of However, conforming client implementations (ie: all web browsers) will refuse to process WebAuthn requests for an RP ID that does not match the In the scenario above with conforming client-side checks, this would force the attacker to change the request's RP ID to SeverityPer WebAuthn §13.4.9:
Unfortunately, the chain needed to exploit this bug makes it difficult to classify with the CVSS framework. Kanidm came up with anywhere between "low" and "high" depending on the approach, and GitHub only provides one CVSS field for everything. An attacker could easily bypass a correctly-implemented server-side However, Due to the complex preconditions and non-default configuration required to execute a successful attack, and that it is not exploitable in popular web browsers, Kanidm considers this a low severity issue. Affected versions
0.6.0-dev
Fixed in
0.5.5
0.6.1-dev
References Updated Sep 10, 2026 · Source: OSV.dev |
0.3.0-alpha.1
unknown
Dependencies (10)
+ 2 more |
|
0.1.2
unknown
1 CVE
GHSA-22w3-693w-x895
May 06, 2026
webauthn-rs-core/webauthn-authenticator-rs: Origin validation mismatch possible when subdomains are allowed
Low
Network
High
None
Summary
This check is flawed, and could allow requests from an attacker-controlled domain such as
These issues are a violation of WebAuthn Level 3 §13.4.9, §5.1.3 Step 8 and §5.1.4.1 Step 7. Details
Origin | RP ID | Expected result | Result with incorrect FixWhen
Regression tests for this bug have been added to both libraries. ImpactWith a both a non-conforming client implementation and vulnerable version of However, conforming client implementations (ie: all web browsers) will refuse to process WebAuthn requests for an RP ID that does not match the In the scenario above with conforming client-side checks, this would force the attacker to change the request's RP ID to SeverityPer WebAuthn §13.4.9:
Unfortunately, the chain needed to exploit this bug makes it difficult to classify with the CVSS framework. Kanidm came up with anywhere between "low" and "high" depending on the approach, and GitHub only provides one CVSS field for everything. An attacker could easily bypass a correctly-implemented server-side However, Due to the complex preconditions and non-default configuration required to execute a successful attack, and that it is not exploitable in popular web browsers, Kanidm considers this a low severity issue. Affected versions
0.6.0-dev
Fixed in
0.5.5
0.6.1-dev
References Updated Sep 10, 2026 · Source: OSV.dev |
0.1.2
unknown
Dependencies (10)
+ 2 more |
|
0.1.1
unknown
1 CVE
GHSA-22w3-693w-x895
May 06, 2026
webauthn-rs-core/webauthn-authenticator-rs: Origin validation mismatch possible when subdomains are allowed
Low
Network
High
None
Summary
This check is flawed, and could allow requests from an attacker-controlled domain such as
These issues are a violation of WebAuthn Level 3 §13.4.9, §5.1.3 Step 8 and §5.1.4.1 Step 7. Details
Origin | RP ID | Expected result | Result with incorrect FixWhen
Regression tests for this bug have been added to both libraries. ImpactWith a both a non-conforming client implementation and vulnerable version of However, conforming client implementations (ie: all web browsers) will refuse to process WebAuthn requests for an RP ID that does not match the In the scenario above with conforming client-side checks, this would force the attacker to change the request's RP ID to SeverityPer WebAuthn §13.4.9:
Unfortunately, the chain needed to exploit this bug makes it difficult to classify with the CVSS framework. Kanidm came up with anywhere between "low" and "high" depending on the approach, and GitHub only provides one CVSS field for everything. An attacker could easily bypass a correctly-implemented server-side However, Due to the complex preconditions and non-default configuration required to execute a successful attack, and that it is not exploitable in popular web browsers, Kanidm considers this a low severity issue. Affected versions
0.6.0-dev
Fixed in
0.5.5
0.6.1-dev
References Updated Sep 10, 2026 · Source: OSV.dev |
0.1.1
unknown
Dependencies (9)
+ 1 more |