PT-2026-45901 · Npm · Morgan

·

CVE-2026-5078

·

Published

2026-06-02

·

Updated

2026-07-10

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions morgan versions 1.2.0 through 1.10.1
Description The logging middleware fails to neutralize control characters when the :remote-user token extracts the Basic auth username from the Authorization request header. An unauthenticated attacker can send a crafted Authorization Basic header containing Carriage Return (CR) or Line Feed (LF) bytes to inject forged log lines. This breaks the one-request-per-line structure of access logs, enabling log forgery against downstream log consumers. The issue affects the built-in combined, common, default, and short formats, as well as any custom format referencing :remote-user.
Recommendations Upgrade to version 1.11.0. As a temporary workaround, use a custom format string that does not include :remote-user.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-5078
GHSA-4VJ7-5MJ6-JM8M

Affected Products

Morgan