30
55
42
57
55
Stytch offers toolkit for developers to build, implement, and customize passkey-based authentication
30
45
30
30
30
30
60
60
57
47
30
57
57
30
30
30
30
60
CVE-2026-86304: MojoX::Authentication versions before 0.006 for Perl allow SAML authentication bypass because parse_assertion builds Net::SAML2::Binding::POST without a trust anchor
MojoX::Authentication before 0.006 for Perl allows SAML authentication bypass because parse_assertion builds Net::SAML2::Binding::POST without a trust anchor (CVE-2026-86304).
CVE-2026-86304 affects MojoX::Authentication versions before 0.006 for Perl. The parse_assertion function builds Net::SAML2::Binding::POST without a trust anchor, so SAML assertions are not validated against a trusted signing key, enabling authentication bypass. The flaw is fixed in version 0.006 of the module.
42
60
55
60
42
60
42
60
55
57
30
30
55
55
57
57
55