#1147520 node-morgan: CVE-2026-87859

Package:
src:node-morgan
Source:
src:node-morgan
Submitter:
Salvatore Bonaccorso
Date:
2026-09-13 09:07:03 UTC
Severity:
normal
Tags:
#1147520#5
Date:
2026-09-12 15:18:09 UTC
From:
To:
Hi,

The following vulnerability was published for node-morgan.

CVE-2026-87859[0]:
| morgan is an HTTP request logger middleware for Node.js. In versions
| before 1.12.1, its escapeLogField() function does not escape the
| double quote character, which delimits the quoted fields of the
| Apache combined log format that morgan emits. An unauthenticated
| remote attacker who controls a value written to a quoted field, such
| as the User-Agent or Referer header, can include a double quote to
| close that field early, so a log consumer that parses the log by
| field position reads attacker-supplied text as the following field.
| In the built-in formats this makes the recorded value differ from
| the value that was sent, and in custom formats that quote an
| attacker-controlled token before a server-controlled one it can
| forge values such as the response status. No newline is injected, so
| record separation stays intact. The issue is fixed in morgan 1.12.1,
| which escapes the double quote. Users should upgrade to morgan
| 1.12.1 or later.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-87859
https://www.cve.org/CVERecord?id=CVE-2026-87859
[1] https://github.com/expressjs/morgan/security/advisories/GHSA-9f6g-j8ch-79g4
[2] https://github.com/expressjs/morgan/commit/4b695edf967ce179cdf4009fe8cddd184b7511ee

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1147520#8
Date:
2026-09-13 08:48:29 UTC
From:
To:
Hello,

Bug #1147520 in node-morgan reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/js-team/node-morgan/-/commit/f14fa0c7e61bf380e3282afd2cd51bba8cefeb0f

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1147520

#1147520#13
Date:
2026-09-13 08:48:28 UTC
From:
To:
Hello,

Bug #1147520 in node-morgan reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/js-team/node-morgan/-/commit/f14fa0c7e61bf380e3282afd2cd51bba8cefeb0f

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1147520

#1147520#18
Date:
2026-09-13 09:05:27 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
node-morgan, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1147520@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Xavier Guimard <yadd@debian.org> (supplier of updated node-morgan package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sun, 13 Sep 2026 10:46:16 +0200
Source: node-morgan
Architecture: source
Version: 1.12.1+~1.9.10-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Javascript Maintainers <pkg-javascript-devel@lists.alioth.debian.org>
Changed-By: Xavier Guimard <yadd@debian.org>
Closes: 1147520
Changes:
 node-morgan (1.12.1+~1.9.10-1) unstable; urgency=medium
 .
   * New upstream version (Closes: #1147520, CVE-2026-87859)
   * Unfuzz patches
Checksums-Sha1:
 7e84a20e578ac8af4bd41586a57c68ef9c918187 2564 node-morgan_1.12.1+~1.9.10-1.dsc
 725c15d95a5e6150237524cd713bc2d68f9edf1a 3377 node-morgan_1.12.1+~1.9.10.orig-types-morgan.tar.gz
 614683f5fe923628ff1b2e52fd69243825a0cf11 25005 node-morgan_1.12.1+~1.9.10.orig.tar.gz
 779ac87e8971464488e96422df5a0b363bcdaf37 3452 node-morgan_1.12.1+~1.9.10-1.debian.tar.xz
Checksums-Sha256:
 94622dcf5ccb3ec00b15d85773871d1e5e1fffb2a0f1bff41688f0dc7beda2f6 2564 node-morgan_1.12.1+~1.9.10-1.dsc
 1887953565972ba24af85c2d3d78f46522b1bb71bee0bf6cc829b77e8eff541d 3377 node-morgan_1.12.1+~1.9.10.orig-types-morgan.tar.gz
 23d54e762d9f03c8ac10e301f226b65d025462746719d94600fb662a19889c6d 25005 node-morgan_1.12.1+~1.9.10.orig.tar.gz
 b18dadf90035403e58352a6ebd90c177218c9c4edc966a3754ba430b1f962648 3452 node-morgan_1.12.1+~1.9.10-1.debian.tar.xz
Files:
 284bccae6629bbe2676afd9a2f698a43 2564 javascript optional node-morgan_1.12.1+~1.9.10-1.dsc
 08fc5d013f0f7edb23228bfb15659ed7 3377 javascript optional node-morgan_1.12.1+~1.9.10.orig-types-morgan.tar.gz
 cfbe1e1a47b5848a6da7ca5a692ca6c5 25005 javascript optional node-morgan_1.12.1+~1.9.10.orig.tar.gz
 8e528c17f6910df604dfa4fb1d09414e 3452 javascript optional node-morgan_1.12.1+~1.9.10-1.debian.tar.xz
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEAN/li4tVV3nRAF7J9tdMp8mZ7ukFAmqmY0EACgkQ9tdMp8mZ
7umEJg/+PXMd0sJ1KC3/uBul8TS0sO/365akpNptFfw21cdYxd6uvL4GNamcdIL7
96iQmOOnh93Uton+R5o66tKjL8HQqmg0/94Fh19rMqD4Bwahcm8kfMmN0Q4/LAc1
jUnG/y50IppYQ34gcMg1rjPp71xtcBT3MM4Xw30789HMYJksK2ge3I1yO1E3IqvW
7qIpKxvkQm+bgvhxgxBO/8gw9OfkJ6wht+B3cL2oy1c+gdtH9n5PQcS7raR2mFr5
F1S4fbz5eBOkQGQ5cuPLRO54Hxe939mrC+tWfzvpFQ5EA3xFVex9RyZBFp2g5+tP
W6/0sEW8+gamnb4nueW2I8L6QLkYPj4ChW0w/qAKxPTnYjzyouaHvkv95vgHYr8t
HZ5VfLYSxQu6ua8AoxtuzHrKvTP5ljACdMX8FZLHzzlZ1jh1YFFmTNBTajjnxpDY
DuA1AuwXt//7MFBuDJVAtdvQuoLuLCd+OAuR9JS0U4AiJ/ktp1IILWQsHUX+XRW6
s+QqnTOvkI7SiWZvQoJkpgb5NkWFqfDeCrWKlRwe0sSDD4ioyukV5v2N8ZoYUfvC
Ivcp364m6GHTKfbAVS/eyWx/nyEe/vQ7yKbaoVMkhGqac0GgP9+txxPSKBlS6IZy
jGh+VbKQixMxw6q31C5+try8SaWPSd9qw/QAY0Z/KdZU1LatIYA=
=WaQ4
-----END PGP SIGNATURE-----