Your message dated Sun, 13 Sep 2026 09:05:27 +0000
with message-id <[email protected]>
and subject line Bug#1147520: fixed in node-morgan 1.12.1+~1.9.10-1
has caused the Debian Bug report #1147520,
regarding node-morgan: CVE-2026-87859
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1147520: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1147520
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: node-morgan
Version: 1.12.0+~1.9.10-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for node-morgan.

CVE-2026-87859[0]:
| morgan is an HTTP request logger middleware for Node.js. In versions
| before 1.12.1, its escapeLogField() function does not escape the
| double quote character, which delimits the quoted fields of the
| Apache combined log format that morgan emits. An unauthenticated
| remote attacker who controls a value written to a quoted field, such
| as the User-Agent or Referer header, can include a double quote to
| close that field early, so a log consumer that parses the log by
| field position reads attacker-supplied text as the following field.
| In the built-in formats this makes the recorded value differ from
| the value that was sent, and in custom formats that quote an
| attacker-controlled token before a server-controlled one it can
| forge values such as the response status. No newline is injected, so
| record separation stays intact. The issue is fixed in morgan 1.12.1,
| which escapes the double quote. Users should upgrade to morgan
| 1.12.1 or later.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-87859
    https://www.cve.org/CVERecord?id=CVE-2026-87859
[1] https://github.com/expressjs/morgan/security/advisories/GHSA-9f6g-j8ch-79g4
[2] 
https://github.com/expressjs/morgan/commit/4b695edf967ce179cdf4009fe8cddd184b7511ee

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

--- End Message ---
--- Begin Message ---
Source: node-morgan
Source-Version: 1.12.1+~1.9.10-1
Done: Xavier Guimard <[email protected]>

We believe that the bug you reported is fixed in the latest version of
node-morgan, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Xavier Guimard <[email protected]> (supplier of updated node-morgan package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Sun, 13 Sep 2026 10:46:16 +0200
Source: node-morgan
Architecture: source
Version: 1.12.1+~1.9.10-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Javascript Maintainers 
<[email protected]>
Changed-By: Xavier Guimard <[email protected]>
Closes: 1147520
Changes:
 node-morgan (1.12.1+~1.9.10-1) unstable; urgency=medium
 .
   * New upstream version (Closes: #1147520, CVE-2026-87859)
   * Unfuzz patches
Checksums-Sha1: 
 7e84a20e578ac8af4bd41586a57c68ef9c918187 2564 node-morgan_1.12.1+~1.9.10-1.dsc
 725c15d95a5e6150237524cd713bc2d68f9edf1a 3377 
node-morgan_1.12.1+~1.9.10.orig-types-morgan.tar.gz
 614683f5fe923628ff1b2e52fd69243825a0cf11 25005 
node-morgan_1.12.1+~1.9.10.orig.tar.gz
 779ac87e8971464488e96422df5a0b363bcdaf37 3452 
node-morgan_1.12.1+~1.9.10-1.debian.tar.xz
Checksums-Sha256: 
 94622dcf5ccb3ec00b15d85773871d1e5e1fffb2a0f1bff41688f0dc7beda2f6 2564 
node-morgan_1.12.1+~1.9.10-1.dsc
 1887953565972ba24af85c2d3d78f46522b1bb71bee0bf6cc829b77e8eff541d 3377 
node-morgan_1.12.1+~1.9.10.orig-types-morgan.tar.gz
 23d54e762d9f03c8ac10e301f226b65d025462746719d94600fb662a19889c6d 25005 
node-morgan_1.12.1+~1.9.10.orig.tar.gz
 b18dadf90035403e58352a6ebd90c177218c9c4edc966a3754ba430b1f962648 3452 
node-morgan_1.12.1+~1.9.10-1.debian.tar.xz
Files: 
 284bccae6629bbe2676afd9a2f698a43 2564 javascript optional 
node-morgan_1.12.1+~1.9.10-1.dsc
 08fc5d013f0f7edb23228bfb15659ed7 3377 javascript optional 
node-morgan_1.12.1+~1.9.10.orig-types-morgan.tar.gz
 cfbe1e1a47b5848a6da7ca5a692ca6c5 25005 javascript optional 
node-morgan_1.12.1+~1.9.10.orig.tar.gz
 8e528c17f6910df604dfa4fb1d09414e 3452 javascript optional 
node-morgan_1.12.1+~1.9.10-1.debian.tar.xz

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEAN/li4tVV3nRAF7J9tdMp8mZ7ukFAmqmY0EACgkQ9tdMp8mZ
7umEJg/+PXMd0sJ1KC3/uBul8TS0sO/365akpNptFfw21cdYxd6uvL4GNamcdIL7
96iQmOOnh93Uton+R5o66tKjL8HQqmg0/94Fh19rMqD4Bwahcm8kfMmN0Q4/LAc1
jUnG/y50IppYQ34gcMg1rjPp71xtcBT3MM4Xw30789HMYJksK2ge3I1yO1E3IqvW
7qIpKxvkQm+bgvhxgxBO/8gw9OfkJ6wht+B3cL2oy1c+gdtH9n5PQcS7raR2mFr5
F1S4fbz5eBOkQGQ5cuPLRO54Hxe939mrC+tWfzvpFQ5EA3xFVex9RyZBFp2g5+tP
W6/0sEW8+gamnb4nueW2I8L6QLkYPj4ChW0w/qAKxPTnYjzyouaHvkv95vgHYr8t
HZ5VfLYSxQu6ua8AoxtuzHrKvTP5ljACdMX8FZLHzzlZ1jh1YFFmTNBTajjnxpDY
DuA1AuwXt//7MFBuDJVAtdvQuoLuLCd+OAuR9JS0U4AiJ/ktp1IILWQsHUX+XRW6
s+QqnTOvkI7SiWZvQoJkpgb5NkWFqfDeCrWKlRwe0sSDD4ioyukV5v2N8ZoYUfvC
Ivcp364m6GHTKfbAVS/eyWx/nyEe/vQ7yKbaoVMkhGqac0GgP9+txxPSKBlS6IZy
jGh+VbKQixMxw6q31C5+try8SaWPSd9qw/QAY0Z/KdZU1LatIYA=
=WaQ4
-----END PGP SIGNATURE-----

Attachment: pgpALPdbny80h.pgp
Description: PGP signature


--- End Message ---
-- 
Pkg-javascript-devel mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-javascript-devel

Reply via email to