• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

zwave-js / zwave-js-ui / 36542665559
13%

Build:
DEFAULT BRANCH: master
Ran 29 Sep 2026 08:26AM UTC
Jobs 1
Files 50
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

29 Sep 2026 08:25AM UTC coverage: 13.161%. Remained the same
36542665559

push

github

web-flow
chore(deps): update dependency morgan to v1.12.1 (#4838)

This PR contains the following updates:

| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [morgan](https://redirect.github.com/expressjs/morgan) | [`1.12.0` →
`1.12.1`](https://renovatebot.com/diffs/npm/morgan/1.12.0/1.12.1) |
![age](https://developer.mend.io/api/mc/badges/age/npm/morgan/1.12.1?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/morgan/1.12.0/1.12.1?slim=true)
|

---

### morgan vulnerable to Log Injection via unescaped double quote in
quoted log fields
[CVE-2026-87859](https://nvd.nist.gov/vuln/detail/CVE-2026-87859) /
[GHSA-9f6g-j8ch-79g4](https://redirect.github.com/advisories/GHSA-9f6g-j8ch-79g4)

<details>
<summary>More information</summary>

#### Details
##### Impact

Morgan writes attacker-controlled request data to the access log. Its
escaping (added in 1.11.0 and 1.12.0) neutralizes control characters,
the Unicode line separators, and backslash, but not the double quote
(`0x22`), which is the field delimiter of the Apache combined log format
morgan emits. An attacker who controls a quoted field (`:user-agent`,
`:referrer`, the request URL, or the Basic auth `:remote-user`) can
inject a double quote to close the field early and forge additional
fields in the log record. The `combined`, `common`, and `default`
formats, and any custom format that quotes a token, are affected. This
is an incomplete fix of CVE-2026-5078 and CVE-2026-15603.

##### Patches

Users should upgrade to version 1.12.1.

##### Workarounds

Update to version 1.12.1.

#### Severity
- CVSS Score: 5.3 / 10 (Medium)
- Vector String: `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N`

#### References
-
[https://github.com/expressjs/morgan/security/advisories/GHSA-9f6g-j8ch-79g4](https://redirect.github.com/expressjs/morgan/security/advisories/GHSA-9f6g-j8ch-79g4)
-
[http... (continued)

537 of 4566 branches covered (11.76%)

Branch coverage included in aggregate %.

991 of 7044 relevant lines covered (14.07%)

2.2 hits per line

Jobs
ID Job ID Ran Files Coverage
1 36542665559.1 29 Sep 2026 08:26AM UTC 50
13.16
GitHub Action Run
Source Files on build 36542665559
  • Tree
  • List 50
  • Changed 0
  • Source Changed 0
  • Coverage Changed 0
Coverage ∆ File Lines Relevant Covered Missed Hits/Line Branch Hits Branch Misses
  • Back to Repo
  • 275faabf on github
  • Prev Build on master (#36532128763)
  • Next Build on master (#36543137922)
  • Delete
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc