« Volver al listado

Morgan Project

Morgan Project Morgan: vulnerabilidades y CVE

Morgan Project Morgan tiene 3 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE3
Últimos 12 meses2
Críticas1
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-15603Media (5.3)0.29%—28 ago 2026
morgan is an HTTP request logger middleware for Node.js. In versions prior to 1.12.0, the internal helper that escapes log token values did not neutralize the Unicode line separator characters U+0085 (Next Line), U+2028…
CVE-2026-5078Media (5.3)0.41%—3 jun 2026
Impact: The morgan logging middleware's :remote-user token extracts the Basic auth username from the Authorization request header and writes it to the log stream without neutralizing control characters. An…
CVE-2019-5413Crítica (9.8)3.4%—21 mar 2019
An attacker can use the format parameter to inject arbitrary commands in the npm package morgan < 1.9.1.