Versions before and including 2.27.0 use a block list of specific keys that should be sanitized from the request object contained in the error object. When a request to Auth0 fails, the key for Authorization header is not sanitized and the Authorization header value can be logged exposing a bearer token.