VYPR
High severity7.5NVD Advisory· Published Jun 26, 2026· Updated Jun 26, 2026

CVE-2026-48615

CVE-2026-48615

Description

A flaw in Node.js proxy tunnel error handling could expose proxy credentials in ERR_PROXY_TUNNEL error messages.

When proxy credentials are embedded in the proxy URL, they may be exposed through error handling paths and captured by logs, diagnostics, or other error consumers.

This vulnerability affects all supported release lines: Node.js 22, Node.js 24, and Node.js 26.

Affected products

28

Patches

Vulnerability mechanics

References

1

News mentions

1