{"id":"GHSA-9f6g-j8ch-79g4","summary":"morgan vulnerable to Log Injection via unescaped double quote in quoted log fields","details":"### Impact\n\nMorgan writes attacker-controlled request data to the access log. Its escaping (added in 1.11.0 and 1.12.0) neutralizes control characters, the Unicode line separators, and backslash, but not the double quote (`0x22`), which is the field delimiter of the Apache combined log format morgan emits. An attacker who controls a quoted field (`:user-agent`, `:referrer`, the request URL, or the Basic auth `:remote-user`) can inject a double quote to close the field early and forge additional fields in the log record. The `combined`, `common`, and `default` formats, and any custom format that quotes a token, are affected. This is an incomplete fix of CVE-2026-5078 and CVE-2026-15603.\n\n### Patches\n\nUsers should upgrade to version 1.12.1.\n\n### Workarounds\n\nUpdate to version 1.12.1.","aliases":["CVE-2026-87859"],"modified":"2026-09-28T21:45:03.858040877Z","published":"2026-09-28T21:33:08Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-09-28T21:33:08Z","nvd_published_at":"2026-09-11T10:16:53Z","cwe_ids":["CWE-117"]},"references":[{"type":"WEB","url":"https://github.com/expressjs/morgan/security/advisories/GHSA-9f6g-j8ch-79g4"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-87859"},{"type":"WEB","url":"https://github.com/expressjs/morgan/commit/4b695edf967ce179cdf4009fe8cddd184b7511ee"},{"type":"WEB","url":"https://cna.openjsf.org/security-advisories.html"},{"type":"PACKAGE","url":"https://github.com/expressjs/morgan"},{"type":"WEB","url":"https://github.com/expressjs/morgan/releases/tag/1.12.1"}],"affected":[{"package":{"name":"morgan","ecosystem":"npm","purl":"pkg:npm/morgan"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.12.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-9f6g-j8ch-79g4/GHSA-9f6g-j8ch-79g4.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"}]}