Executive brief
WebauthnAuthenticator leaks sensitive HTTP headers through INFO-level logs
Affected products
- Packagist web-auth/webauthn-symfony-bundle
Junglewise Threat Intelligence
Severity: medium · CVSS 4 · Published 2026-06-26
Technologies: web-auth/webauthn-symfony-bundle (Packagist). Vendors: Packagist.
WebauthnAuthenticator leaks sensitive HTTP headers through INFO-level logs