Junglewise Threat Intelligence

CVE-2026-87859: morgan HTTP request logger log injection via unescaped double quote

CVE-2026-87859 · Severity: medium · CVSS 5.3 · Published 2026-09-11

Technologies: Expressjs Morgan.

Executive brief

morgan is a Node.js middleware that logs HTTP requests to access logs in Apache combined log format. An attacker can inject unescaped double quotes via request headers (User-Agent, Referer) or request URL to break out of quoted log fields, causing log parsers to misread field values. This can lead to log record forgery, especially if custom log formats quote attacker-controlled data before server-controlled fields like response status or byte counts, enabling attackers to forge values in access logs that automated security tools or log analyzers rely upon.

Technical details

morgan's escapeLogField() function fails to escape double quote characters (0x22) when writing HTTP request data to access logs in Apache combined log format. The vulnerability resides in quoted log fields such as :user-agent, :referrer, :req[...], and request-line. An unauthenticated remote attacker can include a double quote in these headers to prematurely close a quoted field, causing log parsers that rely on field-position parsing (e.g., Logstash grok, SIEM pipelines, log analytics tools) to read attacker-supplied text as the following positional field. In custom log formats that quote an attacker-controlled token before a server-controlled one, this allows forging values like response status or byte count. No newline injection occurs, preserving record separation. The fix in 1.12.1 adds escaping for the double quote character. This is an incomplete fix of prior CVE-2026-15603 and CVE-2026-5078.

Affected products

  • expressjs morgan before 1.12.1

Timeline

  • 2026-09-11: disclosed
  • 2026-09-11: patched: morgan 1.12.1 released with double quote escaping

References