org.openidentityplatform.openam:openam-auth-webauthn
Maven2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.openidentityplatform.openam:openam-auth-webauthnpage 1 of 1
- CVE-2026-45051CRITICALEG not assessed✓ Fixed in 16.1.12026-06-24
vulnerable: 14.5.2 ... 16.1.0 (40 versions)
OpenAM: Pre-auth RCE via Java Deserialization in WebAuthn Authenticator Storage ## Summary **Description** A deserialization of untrusted data vulnerability (CWE-502) exists in OpenAM's WebAuthn authentication module. Under certain cond…
- CVE-2026-62263CRITICALEG not assessed✓ Fixed in 16.1.22026-07-24
vulnerable: 14.5.2 ... 16.1.1 (41 versions)
OpenAM: WebAuthn Java deserialization RCE via ObjectInputFilter depth>1 bypass ### Summary The GHSA-6c99-87fr-6q7r fix wrapped WebAuthn authenticator deserialization in an `ObjectInputFilter` meant to allow only `AuthenticatorImpl`, but i…
Check whether org.openidentityplatform.openam:openam-auth-webauthn is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.openidentityplatform.openam:openam-auth-webauthn CVEs against the assets you own.
Start Free Scan →