Comparison of Object References Instead of Object Contents Affecting org.springframework.security:spring-security-webauthn package, versions [6.4.0,7.0.7)[7.1.0,7.1.1)


Severity

Recommended
0.0
critical
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.3% (23rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-19267401
  • published26 Aug 2026
  • disclosed20 Aug 2026
  • creditYu Bao

Introduced: 20 Aug 2026

New Malicious CVE-2026-47841  (opens in a new tab)
CWE-595  (opens in a new tab)

How to fix?

Avoid using all malicious instances of the org.springframework.security:spring-security-webauthn package.

Overview

Affected versions of this package are vulnerable to Comparison of Object References Instead of Object Contents in the process of comparing UserVerificationRequirement during WebAuthn authentication ceremonies when using distributed HTTP session stores. An attacker can bypass user verification by exploiting the fact that deserialized session objects do not match the expected static constant, causing the verification requirement to be silently disabled. This is only exploitable if the application uses WebAuthn authentication, explicitly sets userVerification to REQUIRED, and utilizes a distributed HTTP session store such as Redis, JDBC, or Hazelcast.

CVSS Base Scores

version 4.0
version 3.1