DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-87859: CVE-2026-87859: Log Injection Vulnerability in Morgan HTTP Request Logger

CVE-2026-87859: Log Injection Vulnerability in Morgan HTTP Request Logger

Vulnerability ID: CVE-2026-87859
CVSS Score: 5.3
Published: 2026-09-28

CVE-2026-87859 is a medium-severity log injection vulnerability in the Node.js morgan HTTP request logger middleware. Prior to version 1.12.1, the internal sanitization utility fails to escape double-quote characters within logged fields, enabling unauthenticated remote attackers to inject arbitrary text, close log fields early, and spoof critical metadata in downstream log parsers.

TL;DR

Unescaped double quotes in morgan log fields allow attackers to forge HTTP status codes and response metrics in access logs, blinding automated SIEM parsers.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-117 (Improper Output Neutralization for Logs)
  • Attack Vector: Network (Unauthenticated)
  • CVSS Score: 5.3 (Medium)
  • EPSS Score: 0.00393 (Percentile: 33.29%)
  • Impact: Low Integrity (Log Spoofing & Manipulation)
  • Exploit Status: PoC Available
  • KEV Status: Not Listed

Affected Systems

  • Node.js applications utilizing morgan middleware for HTTP request logging
  • morgan: < 1.12.1 (Fixed in: 1.12.1)

Code Analysis

Commit: 4b695ed

Fix escapeLogField to handle double-quote characters

Exploit Details

Mitigation Strategies

  • Upgrade the 'morgan' dependency to version 1.12.1 or higher.
  • Use custom log formats that avoid quoting user-controlled headers if upgrading is not immediately possible.
  • Implement log validation downstream to detect anomalous formatting structures.

Remediation Steps:

  1. Locate all project instances using the 'morgan' library.
  2. Execute 'npm install morgan@1.12.1' or update 'package.json' and run 'npm install'.
  3. Verify the installation by checking package-lock.json to ensure no transitive dependencies are resolving to older versions.
  4. Deploy the updated application to production and verify that double quotes are successfully escaped in the generated log output.

References


Read the full report for CVE-2026-87859 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)