[Git][security-tracker-team/security-tracker][master] Add CVE-2026-87859/node-morgan

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Sep 11 22:10:14 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
a5910d09 by Salvatore Bonaccorso at 2026-09-11T23:09:43+02:00
Add CVE-2026-87859/node-morgan

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -123,7 +123,9 @@ CVE-2026-87983 (An arbitrary file read vulnerability in Mistral Vibe, introduced
 CVE-2026-87910 (When tarfile extracts a link on a system that doesn't support links, i ...)
 	TODO: check
 CVE-2026-87859 (morgan is an HTTP request logger middleware for Node.js. In versions b ...)
-	TODO: check
+	- node-morgan <unfixed>
+	NOTE: https://github.com/expressjs/morgan/security/advisories/GHSA-9f6g-j8ch-79g4
+	NOTE: Fixed by: https://github.com/expressjs/morgan/commit/4b695edf967ce179cdf4009fe8cddd184b7511ee (1.12.1)
 CVE-2026-87776 (compression is a Node.js and Express compression middleware. In versio ...)
 	TODO: check
 CVE-2026-87727 (a-blog cms Ver. 3.2.33 and earlier contains a path traversal vulnerabi ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a5910d095ff4cdf92b3e05e419751cd43a9a1fd4

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a5910d095ff4cdf92b3e05e419751cd43a9a1fd4
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260911/e5f6398a/attachment.htm>


More information about the debian-security-tracker-commits mailing list