{"api_version":"v1","generated_at":"2026-10-08T03:10:00+00:00","product":{"cve_count":3,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-morgan-morgan-62cfbb047660","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/morgan","name":"morgan","next_cursor":null,"observations":[{"affected":"morgan: < 1.12.1","affected_versions_present":true,"cve_id":"CVE-2026-87859","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-87859","fixed":"morgan: 1.12.1","last_modified":"2026-09-11T11:32:10.246Z","patch_url":"https://github.com/expressjs/morgan/security/advisories/GHSA-9f6g-j8ch-79g4","primary_source":"","published":"2026-09-11T09:15:19.109Z"},{"affected":"< 1.12.0","affected_versions_present":true,"cve_id":"CVE-2026-15603","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-15603","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-28T18:23:58.959Z","patch_url":"","primary_source":"","published":"2026-08-28T13:41:49.521Z"},{"affected":"1.2.0 \u2264 1.10.1","affected_versions_present":true,"cve_id":"CVE-2026-5078","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-5078","fixed":"1.11.0","last_modified":"2026-06-03T13:19:32.922Z","patch_url":"https://github.com/expressjs/morgan/security/advisories/GHSA-4vj7-5mj6-jm8m","primary_source":"","published":"2026-06-03T05:56:49.512Z"}],"source_generated_at":"2026-10-07T06:21:30.017Z","vendor":"morgan"}}
