| Release | Version |
|---|---|
| bookworm | 1.10.0+~1.9.3-1 |
| trixie | 1.10.0+~1.9.3-1 |
| forky | 1.12.1+~1.9.10-1 |
| sid | 1.12.1+~1.9.10-1 |
| Bug | bookworm | trixie | forky | sid | Description |
|---|---|---|---|---|---|
| CVE-2026-87859 | vulnerable (no DSA, postponed) | vulnerable (no DSA) | fixed | fixed | morgan is an HTTP request logger middleware for Node.js. In versions b ... |
| CVE-2026-15603 | vulnerable (no DSA, postponed) | vulnerable (no DSA) | fixed | fixed | morgan is an HTTP request logger middleware for Node.js. In versions p ... |
| CVE-2026-5078 | vulnerable (no DSA, postponed) | vulnerable (no DSA) | fixed | fixed | Impact: The morgan logging middleware's :remote-user token extracts th ... |
| Bug | Description |
|---|---|
| CVE-2019-5413 | An attacker can use the format parameter to inject arbitrary commands ... |