Junglewise Threat Intelligence

WebauthnAuthenticator leaks sensitive HTTP headers through INFO-level logs

Severity: medium · CVSS 4 · Published 2026-06-26

Technologies: web-auth/webauthn-symfony-bundle (Packagist). Vendors: Packagist.

Executive brief

WebauthnAuthenticator leaks sensitive HTTP headers through INFO-level logs

Affected products

  • Packagist web-auth/webauthn-symfony-bundle

Related threats