CVE-2026-48615 - Node.js Proxy Credentials Exposure via Tunnel Error

CVE Advisories
Post Reply
Starburst-David
Posts: 289
Joined: Wed Feb 11, 2026 8:31 pm

CVE-2026-48615 - Node.js Proxy Credentials Exposure via Tunnel Error

Post by Starburst-David »

CVE ID: CVE-2026-48615
Published: June 26, 2026
Description: A flaw in Node.js proxy tunnel error handling could expose proxy credentials in `ERR_PROXY_TUNNEL` error messages. When proxy credentials are embedded in the proxy URL, they may be exposed through error handling paths and captured by logs, diagnostics, or other error consumers. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.
Severity: 0.0 | NA

More Information:
https://cvefeed.io/vuln/detail/CVE-2026-48615
 

POSTREACT(ions) SUMMARY

Post Reply

Return to “CVE Advisories”