Home
Description
Yubico webauthn-server-core (aka java-webauthn-server) 2.8.0 before 2.8.2 incorrectly checks a function’s return value in the second factor flow, leading to impersonation.
Problem types
CWE-253 Incorrect Check of Function Return Value
Product status
2.8.0 (semver) before 2.8.2
References
www.yubico.com/support/security-advisories/ysa-2026-02/
