Morgan Project

Morgan

3 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.24%
  • Veröffentlicht 28.08.2026 13:41:49
  • Zuletzt bearbeitet 31.08.2026 17:11:12

morgan is an HTTP request logger middleware for Node.js. In versions prior to 1.12.0, the internal helper that escapes log token values did not neutralize the Unicode line separator characters U+0085 (Next Line), U+2028 (Line Separator), and U+2029 (...

  • EPSS 0.33%
  • Veröffentlicht 03.06.2026 05:56:49
  • Zuletzt bearbeitet 22.07.2026 19:10:00

Impact: The morgan logging middleware's :remote-user token extracts the Basic auth username from the Authorization request header and writes it to the log stream without neutralizing control characters. An unauthenticated attacker can send a crafted ...

Exploit
  • EPSS 3.4%
  • Veröffentlicht 21.03.2019 16:01:05
  • Zuletzt bearbeitet 21.11.2024 04:44:53

An attacker can use the format parameter to inject arbitrary commands in the npm package morgan < 1.9.1.