CVE-2026-48615
Vulnerability Summary
Timeline
Description
A flaw in Node.js proxy tunnel error handling could expose proxy credentials in `ERR_PROXY_TUNNEL` error messages. When proxy credentials are embedded in the proxy URL, they may be exposed through error handling paths and captured by logs, diagnostics, or other error consumers. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.
CVSS Metrics
- v3.1•HIGH•Score: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- v3.0•MEDIUM•Score: 5.9CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Trends
Current EPSS score: 0.42%• Percentile: 36%
Techniques & Countermeasures
- CWE-359•Exposure of Private Personal Information to an Unauthorized Actor
The product does not properly prevent a person's private, personal information from being accessed by actors who either (1) are not explicitly authorized to access the information or (2) do not have the implicit consent of the person about whom the information is collected.
Affected Systems
- alpine•nodejs
< 22.23.0-r0 | < 22.23.0-r0 | < 24.17.0-r0 | < 24.17.0-r0
- debian•nodejs
< 24.17.0+dfsg+~cs24.13.2-1
- nodejs•node
22.22.3 | 24.16.0 | 26.3.0
- nodejs•node.js
22.22.3 | 24.16.0 | 26.3.0