PUBLISHED
Published: 26 Jun 2026, 01:14
Last modified:26 Jun 2026, 13:35

Vulnerability Summary

Overall Risk (default)
low
24/100
CVSS Score
5.9 MEDIUM
v3.0 (cve.org)
EPSS Score
0.44% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

26 Jun 2026, 01:14
Published
Vulnerability first disclosed
26 Jun 2026, 13:35
Last Modified
Vulnerability information updated

Description

A flaw in Node.js proxy tunnel error handling could expose proxy credentials in `ERR_PROXY_TUNNEL` error messages. When proxy credentials are embedded in the proxy URL, they may be exposed through error handling paths and captured by logs, diagnostics, or other error consumers. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

CVSS Metrics

  • v3.0MEDIUMScore: 5.9CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS Trends

Current EPSS score: 0.44% Percentile: 35%

Techniques & Countermeasures

  • CWE-359Exposure of Private Personal Information to an Unauthorized Actor

    The product does not properly prevent a person's private, personal information from being accessed by actors who either (1) are not explicitly authorized to access the information or (2) do not have the implicit consent of the person about whom the information is collected.

Affected Systems

  • nodejsnode

    22.22.3 | 24.16.0 | 26.3.0

References (1)