Improper Output Neutralization for Logs in morgan - CVE-2026-5078
Published: August 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to forge log entries.
The vulnerability exists due to improper output neutralization for logs in the :remote-user token when processing a crafted Authorization header. A remote attacker can send a crafted Authorization: Basic header containing CR/LF characters to forge log entries.
The built-in combined, common, default, and short formats are affected, as well as custom formats that include :remote-user.