morgan vulnerable to Log Forging via unneutralized control characters in :remote-user
Description
Published by the National Vulnerability Database
Jun 3, 2026
Published to the GitHub Advisory Database
Jul 10, 2026
Reviewed
Jul 10, 2026
Last updated
Jul 10, 2026
Impact
Morgan's
:remote-usertoken extracts the Basic auth username from theAuthorizationheader and writes it to the log stream without neutralizing control characters. An attacker can send a craftedAuthorization: Basicheader containing CR/LF characters to inject forged log lines, corrupting the one-request-per-line structure of access logs.The built-in
combined,common,default, andshortformats are affected, as well as any custom format that includes:remote-user.Patches
Users should upgrade to version 1.11.0.
Workarounds
Use a custom format string that does not include
:remote-user.References