morgan
3 known vulnerabilities in morgan, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-87859 CVSS 5.3 medium morgan is an HTTP request logger middleware for Node.js. In versions before 1.12.1, its escapeLogField() function does not escape the…
- CVE-2026-15603 CVSS 5.3 medium morgan is an HTTP request logger middleware for Node.js. In versions prior to 1.12.0, the internal helper that escapes log token values…
- CVE-2026-5078 CVSS 5.3 medium Impact: The morgan logging middleware's :remote-user token extracts the Basic auth username from the Authorization request header and…