- Package:
- src:node-morgan
- Source:
- src:node-morgan
- Submitter:
- Salvatore Bonaccorso
- Date:
- 2026-09-13 09:07:03 UTC
- Severity:
- normal
- Tags:
Hi, The following vulnerability was published for node-morgan. CVE-2026-87859[0]: | morgan is an HTTP request logger middleware for Node.js. In versions | before 1.12.1, its escapeLogField() function does not escape the | double quote character, which delimits the quoted fields of the | Apache combined log format that morgan emits. An unauthenticated | remote attacker who controls a value written to a quoted field, such | as the User-Agent or Referer header, can include a double quote to | close that field early, so a log consumer that parses the log by | field position reads attacker-supplied text as the following field. | In the built-in formats this makes the recorded value differ from | the value that was sent, and in custom formats that quote an | attacker-controlled token before a server-controlled one it can | forge values such as the response status. No newline is injected, so | record separation stays intact. The issue is fixed in morgan 1.12.1, | which escapes the double quote. Users should upgrade to morgan | 1.12.1 or later. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-87859 https://www.cve.org/CVERecord?id=CVE-2026-87859 [1] https://github.com/expressjs/morgan/security/advisories/GHSA-9f6g-j8ch-79g4 [2] https://github.com/expressjs/morgan/commit/4b695edf967ce179cdf4009fe8cddd184b7511ee Please adjust the affected versions in the BTS as needed. Regards, Salvatore
Hello, Bug #1147520 in node-morgan reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/js-team/node-morgan/-/commit/f14fa0c7e61bf380e3282afd2cd51bba8cefeb0f (this message was generated automatically) -- Greetings https://bugs.debian.org/1147520
Hello, Bug #1147520 in node-morgan reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/js-team/node-morgan/-/commit/f14fa0c7e61bf380e3282afd2cd51bba8cefeb0f (this message was generated automatically) -- Greetings https://bugs.debian.org/1147520
We believe that the bug you reported is fixed in the latest version of node-morgan, which is due to be installed in the Debian FTP archive. A summary of the changes between this version and the previous one is attached. Thank you for reporting the bug, which will now be closed. If you have further comments please address them to 1147520@bugs.debian.org, and the maintainer will reopen the bug report if appropriate. Debian distribution maintenance software pp. Xavier Guimard <yadd@debian.org> (supplier of updated node-morgan package) (This message was generated automatically at their request; if you believe that there is a problem with it please contact the archive administrators by mailing ftpmaster@ftp-master.debian.org) Format: 1.8 Date: Sun, 13 Sep 2026 10:46:16 +0200 Source: node-morgan Architecture: source Version: 1.12.1+~1.9.10-1 Distribution: unstable Urgency: medium Maintainer: Debian Javascript Maintainers <pkg-javascript-devel@lists.alioth.debian.org> Changed-By: Xavier Guimard <yadd@debian.org> Closes: 1147520 Changes: node-morgan (1.12.1+~1.9.10-1) unstable; urgency=medium . * New upstream version (Closes: #1147520, CVE-2026-87859) * Unfuzz patches Checksums-Sha1: 7e84a20e578ac8af4bd41586a57c68ef9c918187 2564 node-morgan_1.12.1+~1.9.10-1.dsc 725c15d95a5e6150237524cd713bc2d68f9edf1a 3377 node-morgan_1.12.1+~1.9.10.orig-types-morgan.tar.gz 614683f5fe923628ff1b2e52fd69243825a0cf11 25005 node-morgan_1.12.1+~1.9.10.orig.tar.gz 779ac87e8971464488e96422df5a0b363bcdaf37 3452 node-morgan_1.12.1+~1.9.10-1.debian.tar.xz Checksums-Sha256: 94622dcf5ccb3ec00b15d85773871d1e5e1fffb2a0f1bff41688f0dc7beda2f6 2564 node-morgan_1.12.1+~1.9.10-1.dsc 1887953565972ba24af85c2d3d78f46522b1bb71bee0bf6cc829b77e8eff541d 3377 node-morgan_1.12.1+~1.9.10.orig-types-morgan.tar.gz 23d54e762d9f03c8ac10e301f226b65d025462746719d94600fb662a19889c6d 25005 node-morgan_1.12.1+~1.9.10.orig.tar.gz b18dadf90035403e58352a6ebd90c177218c9c4edc966a3754ba430b1f962648 3452 node-morgan_1.12.1+~1.9.10-1.debian.tar.xz Files: 284bccae6629bbe2676afd9a2f698a43 2564 javascript optional node-morgan_1.12.1+~1.9.10-1.dsc 08fc5d013f0f7edb23228bfb15659ed7 3377 javascript optional node-morgan_1.12.1+~1.9.10.orig-types-morgan.tar.gz cfbe1e1a47b5848a6da7ca5a692ca6c5 25005 javascript optional node-morgan_1.12.1+~1.9.10.orig.tar.gz 8e528c17f6910df604dfa4fb1d09414e 3452 javascript optional node-morgan_1.12.1+~1.9.10-1.debian.tar.xz -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEAN/li4tVV3nRAF7J9tdMp8mZ7ukFAmqmY0EACgkQ9tdMp8mZ 7umEJg/+PXMd0sJ1KC3/uBul8TS0sO/365akpNptFfw21cdYxd6uvL4GNamcdIL7 96iQmOOnh93Uton+R5o66tKjL8HQqmg0/94Fh19rMqD4Bwahcm8kfMmN0Q4/LAc1 jUnG/y50IppYQ34gcMg1rjPp71xtcBT3MM4Xw30789HMYJksK2ge3I1yO1E3IqvW 7qIpKxvkQm+bgvhxgxBO/8gw9OfkJ6wht+B3cL2oy1c+gdtH9n5PQcS7raR2mFr5 F1S4fbz5eBOkQGQ5cuPLRO54Hxe939mrC+tWfzvpFQ5EA3xFVex9RyZBFp2g5+tP W6/0sEW8+gamnb4nueW2I8L6QLkYPj4ChW0w/qAKxPTnYjzyouaHvkv95vgHYr8t HZ5VfLYSxQu6ua8AoxtuzHrKvTP5ljACdMX8FZLHzzlZ1jh1YFFmTNBTajjnxpDY DuA1AuwXt//7MFBuDJVAtdvQuoLuLCd+OAuR9JS0U4AiJ/ktp1IILWQsHUX+XRW6 s+QqnTOvkI7SiWZvQoJkpgb5NkWFqfDeCrWKlRwe0sSDD4ioyukV5v2N8ZoYUfvC Ivcp364m6GHTKfbAVS/eyWx/nyEe/vQ7yKbaoVMkhGqac0GgP9+txxPSKBlS6IZy jGh+VbKQixMxw6q31C5+try8SaWPSd9qw/QAY0Z/KdZU1LatIYA= =WaQ4 -----END PGP SIGNATURE-----