SCA: security update for morgan (GHSA-9f6g-j8ch-79g4)

medium Tenable Self-Hosted Container Security Plugin ID 448457

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- morgan is an HTTP request logger middleware for Node.js. In versions before 1.12.1, its escapeLogField()
function does not escape the double quote character, which delimits the quoted fields of the Apache
combined log format that morgan emits. An unauthenticated remote attacker who controls a value written to
a quoted field, such as the User-Agent or Referer header, can include a double quote to close that field
early, so a log consumer that parses the log by field position reads attacker-supplied text as the
following field. In the built-in formats this makes the recorded value differ from the value that was
sent, and in custom formats that quote an attacker-controlled token before a server-controlled one it can
forge values such as the response status. No newline is injected, so record separation stays intact. The
issue is fixed in morgan 1.12.1, which escapes the double quote. Users should upgrade to morgan 1.12.1 or
later. (CVE-2026-87859)

Solution

Update the morgan library and its related packages to version 1.12.1 or later.

See Also

https://github.com/advisories/GHSA-9f6g-j8ch-79g4

Plugin Details

Severity: Medium

ID: 448457

Version: Revision 1.1

Type: Local

Family: SCA Checks

Published: 9/29/2026

Updated: 9/29/2026

Risk Information

VPR

Risk Factor: Low

Score: 1.2

Percentile: 0.01

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N

CVSS Score Source: CVE-2026-87859

CVSS v3

Risk Factor: Medium

Base Score: 5.3

Temporal Score: 4.6

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 9/28/2026

Vulnerability Publication Date: 9/11/2026

Reference Information

CVE: CVE-2026-87859

cwe: CWE-117