216.73.216.226

CVE-2026-5078

· Published 03/06/2026 08:16 · Modified 04/06/2026 19:24

Labels: CVE-2026-5078 2026-06-03CVE-2026-5078CWE-117ce714d77-add3-4f53-aff5-83d477b104bb

Essential information

Published
03/06/2026 08:16
Modified
04/06/2026 19:24
Author
Creator
CVSS
5.3 MEDIUM (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

CVSS metrics

Description

Impact: The morgan logging middleware's :remote-user token extracts the Basic auth username from the Authorization request header and writes it to the log stream without neutralizing control characters. An unauthenticated attacker can send a crafted Authorization Basic header containing CR or LF bytes to inject forged log lines, breaking the one-request-per-line structure of access logs and enabling log forgery against downstream log consumers. The built-in combined, common, default, and short formats are affected, as well as any custom format that references :remote-user. Affected versions: morgan 1.2.0 through 1.10.1. Patches: upgrade to morgan 1.11.0, which neutralizes control characters in the :remote-user token output. Workarounds: use a custom format string that does not include :remote-user.

NVD status

Status
Analyzed — CVE has been recently published to the CVE List and has been received by the NVD.
Source
ce714d77-add3-4f53-aff5-83d477b104bb
NVD
View on NVD

Affected products (CPE)

ProductCPE
morgan project / morgan cpe:2.3:a:morgan_project:morgan:*:*:*:*:*:node.js:*:*

References