{"id":"GHSA-q683-8468-r6h6","summary":"WebauthnAuthenticator leaks sensitive HTTP headers through INFO-level logs","details":"## Impact\n\n`Webauthn\\Bundle\\Security\\Http\\Authenticator\\WebauthnAuthenticator` logs the full `Symfony\\Component\\HttpFoundation\\Request` object inside the log context of both `onAuthenticationSuccess()` and `onAuthenticationFailure()` at INFO level:\n\n```php\n$this-\u003elogger-\u003einfo('User has been authenticated successfully with Webauthn.', [\n    'request' =\u003e $request,\n    'firewallName' =\u003e $firewallName,\n    'identifier' =\u003e $token-\u003egetUserIdentifier(),\n]);\n\n$this-\u003elogger-\u003einfo('Webauthn authentication request failed.', [\n    'request' =\u003e $request,\n    'exception' =\u003e $exception,\n]);\n```\n\n`Request::__toString()` returns the raw HTTP message, including every request header. As soon as the configured logger normalises or stringifies the context (default behaviour for `LineFormatter`, `JsonFormatter` via `NormalizerFormatter`, etc.), sensitive headers such as `Cookie` (session identifier), `Authorization` and any custom auth header are written to the log stream in clear text.\n\nApplications that forward logs to centralised platforms (ELK, Splunk, Datadog and similar) are particularly exposed: log access is typically broader than application access, which can allow log readers to hijack authenticated sessions.\n\n## Affected versions\n\nEvery release prior to 5.3.4 is affected.\n\n## Patches\n\nThe fix removes the full `Request` object from the log context and keeps only non-sensitive fields (request path, method, firewall name, user identifier). It is shipped in 5.3.4. Older branches will not receive a backport; users on those branches should upgrade to 5.3.4+ or apply one of the workarounds below.\n\n## Workarounds\n\nUntil the upgrade is applied, projects can:\n\n1. Raise the minimum log level for the WebAuthn authenticator above INFO so these two log records are not emitted in production.\n2. Configure their Monolog processor/formatter to strip the `request` key from the context of these records before they are written.\n\n## Credit\n\nReported by Kay Joosten (Dawn Technology), maintainer of [Stepup-Webauthn](https://github.com/OpenConext/Stepup-Webauthn).","modified":"2026-09-10T03:50:50.195125618Z","published":"2026-06-26T21:00:49Z","database_specific":{"github_reviewed_at":"2026-06-26T21:00:49Z","nvd_published_at":null,"cwe_ids":["CWE-200","CWE-532"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/web-auth/webauthn-framework/security/advisories/GHSA-q683-8468-r6h6"},{"type":"PACKAGE","url":"https://github.com/web-auth/webauthn-framework"}],"affected":[{"package":{"name":"web-auth/webauthn-symfony-bundle","ecosystem":"Packagist","purl":"pkg:composer/web-auth/webauthn-symfony-bundle"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.3.4"}]}],"versions":["4.1.0","4.1.1","4.1.2","4.1.3","4.1.4","4.1.5","4.2.0","4.2.1","4.2.2","4.2.3","4.3.0","4.3.1","4.4.0","4.4.1","4.4.2","4.4.3","4.5.0","4.5.1","4.5.2","4.6.0","4.6.1","4.6.2","4.6.3","4.6.4","4.7.0","4.7.1","4.7.2","4.7.3","4.7.4","4.7.5","4.7.6","4.7.7","4.7.8","4.7.9","4.8.0","4.8.1","4.8.2","4.8.3","4.8.4","4.8.5","4.8.6","4.8.7","4.9.0","4.9.1","4.9.2","4.9.3","5.0.0","5.0.1","5.1.0","5.1.1","5.1.2","5.1.3","5.2.0","5.2.1","5.2.2","5.2.3","5.2.4","5.2.5","5.2.6","5.3.0","5.3.1","5.3.2","5.3.3","v1.0.0","v1.0.1","v1.1.0","v1.1.0-alpha1","v1.2.0","v1.2.1","v1.2.2","v2.0.0","v2.0.0-alpha1","v2.0.1","v2.0.2","v2.0.3","v2.1.0","v2.1.1","v2.1.2","v2.1.3","v2.1.4","v2.1.5","v2.1.6","v2.1.7","v3.0.0","v3.0.1","v3.0.2","v3.1.0","v3.1.1","v3.2.0","v3.2.1","v3.2.10","v3.2.11","v3.2.12","v3.2.2","v3.2.3","v3.2.4","v3.2.5","v3.2.6","v3.2.7","v3.2.8","v3.2.9","v3.3.0","v3.3.1","v3.3.10","v3.3.11","v3.3.12","v3.3.2","v3.3.3","v3.3.4","v3.3.5","v3.3.6","v3.3.7","v3.3.8","v3.3.9","v4.0.0","v4.0.1","v4.0.2","v4.0.3","v4.0.4","v4.0.5"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-q683-8468-r6h6/GHSA-q683-8468-r6h6.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U"}]}