THREAT OPS › Threat News › [GHSA] GHSA-jxfw-x594-9x9m (medium) — morgan vulnerable to Log Forging via unescaped Unicode line separators
[GHSA] GHSA-jxfw-x594-9x9m (medium) — morgan vulnerable to Log Forging via unescaped Unicode line separators
GHSA-jxfw-x594-9x9m Severity: medium CVE: CVE-2026-15603
morgan vulnerable to Log Forging via unescaped Unicode line separators
### Impact
Morgan writes attacker-controlled request data to the access log through its tokens. The 1.11.0 fix neutralizes C0 control characters, DEL, and backslash, but it does not escape the Unicode line separators `U+0085` (NEL), `U+2028` (LINE SEPARATOR), or `U+202
Indicators of compromise
- CVE-2026-15603cve
- CVE-2026-5078cve
Original source: https://github.com/advisories/GHSA-jxfw-x594-9x9m