{"id":"GHSA-4vj7-5mj6-jm8m","summary":"morgan vulnerable to Log Forging via unneutralized control characters in :remote-user","details":"### Impact\n\nMorgan's `:remote-user` token extracts the Basic auth username from the `Authorization` header and writes it to the log stream without neutralizing control characters. An attacker can send a crafted `Authorization: Basic` header containing CR/LF characters to inject forged log lines, corrupting the one-request-per-line structure of access logs.\n\nThe built-in `combined`, `common`, `default`, and `short` formats are affected, as well as any custom format that includes `:remote-user`.\n\n### Patches\n\nUsers should upgrade to version 1.11.0.\n\n### Workarounds\n\nUse a custom format string that does not include `:remote-user`.","aliases":["CVE-2026-5078"],"modified":"2026-07-10T14:48:23.841115726Z","published":"2026-07-10T14:32:15Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-07-10T14:32:15Z","nvd_published_at":"2026-06-03T08:16:19Z","cwe_ids":["CWE-117"],"severity":"MODERATE"},"references":[{"type":"WEB","url":"https://github.com/expressjs/morgan/security/advisories/GHSA-4vj7-5mj6-jm8m"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-5078"},{"type":"WEB","url":"https://cna.openjsf.org/security-advisories.html"},{"type":"PACKAGE","url":"https://github.com/expressjs/morgan"}],"affected":[{"package":{"name":"morgan","ecosystem":"npm","purl":"pkg:npm/morgan"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.2.0"},{"fixed":"1.11.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-4vj7-5mj6-jm8m/GHSA-4vj7-5mj6-jm8m.json","last_known_affected_version_range":"\u003c= 1.10.1"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"}]}