THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-jxfw-x594-9x9m (medium) — morgan vulnerable to Log Forging via unescaped Unicode line separators

[GHSA] GHSA-jxfw-x594-9x9m (medium) — morgan vulnerable to Log Forging via unescaped Unicode line separators

medgithub_advisoriesPublished 2026-09-08

GHSA-jxfw-x594-9x9m Severity: medium CVE: CVE-2026-15603

morgan vulnerable to Log Forging via unescaped Unicode line separators

### Impact

Morgan writes attacker-controlled request data to the access log through its tokens. The 1.11.0 fix neutralizes C0 control characters, DEL, and backslash, but it does not escape the Unicode line separators `U+0085` (NEL), `U+2028` (LINE SEPARATOR), or `U+202

Indicators of compromise

Original source: https://github.com/advisories/GHSA-jxfw-x594-9x9m