Skip to main content

Vendor/product archive

morgan_project / morgan CVEs

Beta · best-effort

2 CVEs tagged to morgan_project / morgan1 Critical, 0 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2026-5078

Published Jun 3, 2026

Impact: The morgan logging middleware's :remote-user token extracts the Basic auth username from the Authorization request header and writes it to the log stream without neutraliz…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort
Showing 1-2 of 2 CVEsPage 1 of 1