Debian Package Tracker
Register | Log in
Subscribe

node-morgan

HTTP request logger middleware for node.js

Choose email to subscribe with

general
  • source: node-morgan (main)
  • version: 1.10.1+~1.9.10-1
  • maintainer: Debian Javascript Maintainers (archive) (DMD)
  • arch: all
  • std-ver: 4.7.3
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 1.10.0-2
  • oldstable: 1.10.0+~1.9.3-1
  • stable: 1.10.0+~1.9.3-1
  • testing: 1.10.1+~1.9.10-1
  • unstable: 1.10.1+~1.9.10-1
versioned links
  • 1.10.0-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.10.0+~1.9.3-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.10.1+~1.9.10-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • node-morgan
action needed
A new upstream version is available: 1.11.0+~1.9.10 high
A new upstream version 1.11.0+~1.9.10 is available, you should consider packaging it.
Created: 2026-06-03 Last update: 2026-08-29 18:03
1 security issue in trixie high

There is 1 open security issue in trixie.

1 important issue:
  • CVE-2026-15603: morgan is an HTTP request logger middleware for Node.js. In versions prior to 1.12.0, the internal helper that escapes log token values did not neutralize the Unicode line separator characters U+0085 (Next Line), U+2028 (Line Separator), and U+2029 (Paragraph Separator). An unauthenticated remote client can place these characters in an attacker-controlled log token, for example a Basic auth username surfaced through the remote-user token, so that Unicode-aware downstream log processing splits a single request log into multiple logical records. This is a log forging issue (CWE-117) and an incomplete-fix follow-up to CVE-2026-5078, which only addressed ASCII control characters. The issue is fixed in morgan 1.12.0, which extends the escaping set to cover these Unicode line separators. Upgrade to morgan 1.12.0 to remediate.
Created: 2026-08-29 Last update: 2026-08-29 11:30
1 security issue in sid high

There is 1 open security issue in sid.

1 important issue:
  • CVE-2026-15603: morgan is an HTTP request logger middleware for Node.js. In versions prior to 1.12.0, the internal helper that escapes log token values did not neutralize the Unicode line separator characters U+0085 (Next Line), U+2028 (Line Separator), and U+2029 (Paragraph Separator). An unauthenticated remote client can place these characters in an attacker-controlled log token, for example a Basic auth username surfaced through the remote-user token, so that Unicode-aware downstream log processing splits a single request log into multiple logical records. This is a log forging issue (CWE-117) and an incomplete-fix follow-up to CVE-2026-5078, which only addressed ASCII control characters. The issue is fixed in morgan 1.12.0, which extends the escaping set to cover these Unicode line separators. Upgrade to morgan 1.12.0 to remediate.
Created: 2026-08-29 Last update: 2026-08-29 11:30
1 security issue in forky high

There is 1 open security issue in forky.

1 important issue:
  • CVE-2026-15603: morgan is an HTTP request logger middleware for Node.js. In versions prior to 1.12.0, the internal helper that escapes log token values did not neutralize the Unicode line separator characters U+0085 (Next Line), U+2028 (Line Separator), and U+2029 (Paragraph Separator). An unauthenticated remote client can place these characters in an attacker-controlled log token, for example a Basic auth username surfaced through the remote-user token, so that Unicode-aware downstream log processing splits a single request log into multiple logical records. This is a log forging issue (CWE-117) and an incomplete-fix follow-up to CVE-2026-5078, which only addressed ASCII control characters. The issue is fixed in morgan 1.12.0, which extends the escaping set to cover these Unicode line separators. Upgrade to morgan 1.12.0 to remediate.
Created: 2026-08-29 Last update: 2026-08-29 11:30
1 security issue in bullseye high

There is 1 open security issue in bullseye.

1 important issue:
  • CVE-2026-15603: morgan is an HTTP request logger middleware for Node.js. In versions prior to 1.12.0, the internal helper that escapes log token values did not neutralize the Unicode line separator characters U+0085 (Next Line), U+2028 (Line Separator), and U+2029 (Paragraph Separator). An unauthenticated remote client can place these characters in an attacker-controlled log token, for example a Basic auth username surfaced through the remote-user token, so that Unicode-aware downstream log processing splits a single request log into multiple logical records. This is a log forging issue (CWE-117) and an incomplete-fix follow-up to CVE-2026-5078, which only addressed ASCII control characters. The issue is fixed in morgan 1.12.0, which extends the escaping set to cover these Unicode line separators. Upgrade to morgan 1.12.0 to remediate.
Created: 2026-08-29 Last update: 2026-08-29 11:30
1 security issue in bookworm high

There is 1 open security issue in bookworm.

1 important issue:
  • CVE-2026-15603: morgan is an HTTP request logger middleware for Node.js. In versions prior to 1.12.0, the internal helper that escapes log token values did not neutralize the Unicode line separator characters U+0085 (Next Line), U+2028 (Line Separator), and U+2029 (Paragraph Separator). An unauthenticated remote client can place these characters in an attacker-controlled log token, for example a Basic auth username surfaced through the remote-user token, so that Unicode-aware downstream log processing splits a single request log into multiple logical records. This is a log forging issue (CWE-117) and an incomplete-fix follow-up to CVE-2026-5078, which only addressed ASCII control characters. The issue is fixed in morgan 1.12.0, which extends the escaping set to cover these Unicode line separators. Upgrade to morgan 1.12.0 to remediate.
Created: 2026-08-29 Last update: 2026-08-29 11:30
lintian reports 1 error high
Lintian reports 1 error about this package. You should make the package lintian clean getting rid of them.
Created: 2026-03-21 Last update: 2026-03-21 23:01
Multiarch hinter reports 1 issue(s) normal
There are issues with the multiarch metadata for this package.
  • node-morgan could be marked Multi-Arch: foreign
Created: 2025-07-19 Last update: 2026-08-29 16:00
debian/patches: 1 patch to forward upstream low

Among the 1 debian patch available in version 1.10.1+~1.9.10-1 of the package, we noticed the following issues:

  • 1 patch where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2023-02-26 Last update: 2026-03-21 18:00
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.7.4 instead of 4.7.3).
Created: 2026-03-31 Last update: 2026-03-31 15:01
news
[rss feed]
  • [2026-03-24] node-morgan 1.10.1+~1.9.10-1 MIGRATED to testing (Debian testing watch)
  • [2026-03-21] Accepted node-morgan 1.10.1+~1.9.10-1 (source) into unstable (Xavier Guimard)
  • [2022-11-02] node-morgan 1.10.0+~1.9.3-1 MIGRATED to testing (Debian testing watch)
  • [2022-10-31] Accepted node-morgan 1.10.0+~1.9.3-1 (source) into unstable (Yadd) (signed by: Xavier Guimard)
  • [2022-03-26] node-morgan 1.10.0-3 MIGRATED to testing (Debian testing watch)
  • [2022-03-23] Accepted node-morgan 1.10.0-3 (source) into unstable (Yadd) (signed by: Xavier Guimard)
  • [2020-11-04] node-morgan 1.10.0-2 MIGRATED to testing (Debian testing watch)
  • [2020-11-02] Accepted node-morgan 1.10.0-2 (source) into unstable (Andrius Merkys)
  • [2020-10-31] Accepted node-morgan 1.10.0-1 (source all) into unstable, unstable (Debian FTP Masters) (signed by: Andrius Merkys)
bugs [bug history graph]
  • all: 0
links
  • homepage
  • lintian (1, 0)
  • buildd: logs, reproducibility
  • popcon
  • browse source code
  • other distros
  • security tracker
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 1.10.1+~1.9.10-1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing