CVE-2026-87859: Log Injection Vulnerability in Morgan HTTP Request Logger
Vulnerability ID: CVE-2026-87859
CVSS Score: 5.3
Published: 2026-09-28
CVE-2026-87859 is a medium-severity log injection vulnerability in the Node.js morgan HTTP request logger middleware. Prior to version 1.12.1, the internal sanitization utility fails to escape double-quote characters within logged fields, enabling unauthenticated remote attackers to inject arbitrary text, close log fields early, and spoof critical metadata in downstream log parsers.
TL;DR
Unescaped double quotes in morgan log fields allow attackers to forge HTTP status codes and response metrics in access logs, blinding automated SIEM parsers.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-117 (Improper Output Neutralization for Logs)
- Attack Vector: Network (Unauthenticated)
- CVSS Score: 5.3 (Medium)
- EPSS Score: 0.00393 (Percentile: 33.29%)
- Impact: Low Integrity (Log Spoofing & Manipulation)
- Exploit Status: PoC Available
- KEV Status: Not Listed
Affected Systems
- Node.js applications utilizing morgan middleware for HTTP request logging
-
morgan: < 1.12.1 (Fixed in:
1.12.1)
Code Analysis
Commit: 4b695ed
Fix escapeLogField to handle double-quote characters
Exploit Details
- GitHub Security Advisory (GHSA-9f6g-j8ch-79g4): Advisory details documenting the proof of concept and units tests used to verify the escapeLogField breakout.
Mitigation Strategies
- Upgrade the 'morgan' dependency to version 1.12.1 or higher.
- Use custom log formats that avoid quoting user-controlled headers if upgrading is not immediately possible.
- Implement log validation downstream to detect anomalous formatting structures.
Remediation Steps:
- Locate all project instances using the 'morgan' library.
- Execute 'npm install morgan@1.12.1' or update 'package.json' and run 'npm install'.
- Verify the installation by checking package-lock.json to ensure no transitive dependencies are resolving to older versions.
- Deploy the updated application to production and verify that double quotes are successfully escaped in the generated log output.
References
- GitHub Security Advisory GHSA-9f6g-j8ch-79g4
- Fix Commit in Morgan Repository
- Release Tag 1.12.1
- OpenJS Foundation Advisory Portal
- NVD CVE-2026-87859 Details
Read the full report for CVE-2026-87859 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)