CVE-2026-48615
Advisory lineage Upstream: 0 Downstream: 24
PUBLISHED
Published: 26 Jun 2026, 01:14
Last modified:26 Jun 2026, 13:35
Vulnerability Summary
Overall Risk (default)
low
24/100 CVSS Score
5.9 MEDIUM
v3.0 (cve.org)
EPSS Score
0.44% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
26 Jun 2026, 01:14
Published
Vulnerability first disclosed
26 Jun 2026, 13:35
Last Modified
Vulnerability information updated
Description
A flaw in Node.js proxy tunnel error handling could expose proxy credentials in `ERR_PROXY_TUNNEL` error messages. When proxy credentials are embedded in the proxy URL, they may be exposed through error handling paths and captured by logs, diagnostics, or other error consumers. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.
CVSS Metrics
- v3.0•MEDIUM•Score: 5.9CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Trends
Current EPSS score: 0.44%• Percentile: 35%
Techniques & Countermeasures
- CWE-359•Exposure of Private Personal Information to an Unauthorized Actor
The product does not properly prevent a person's private, personal information from being accessed by actors who either (1) are not explicitly authorized to access the information or (2) do not have the implicit consent of the person about whom the information is collected.
Affected Systems
- nodejs•node
22.22.3 | 24.16.0 | 26.3.0