openam webauthn deserialization through a shallow filter
cve-2026-62263 showed that the openam webauthn deserialization filter only constrained the root object, leaving nested gadget graphs unchecked
vulnerability cve web exploitation deserialization