#VU128265 Observable Response Discrepancy in Webauthn Framework - CVE-2024-39912
Published: July 14, 2024 / Updated: April 28, 2026
Webauthn Framework
Web-Authentication
Description
The vulnerability allows a remote attacker to enumerate valid usernames.
The vulnerability exists due to observable response discrepancy in ProfileBasedRequestOptionsBuilder when handling assertion options requests with a supplied username. A remote attacker can send a specially crafted request to enumerate valid usernames.
The issue is exposed when WebAuthn is used as the first or only authentication method.