Aller au contenu

Fiche vulnérabilité

CVE-2026-48615 : faille élevée nodejs node.js (CVSS 7.5)

Description

A flaw in Node.js proxy tunnel error handling could expose proxy credentials in `ERR_PROXY_TUNNEL` error messages. When proxy credentials are embedded in the proxy URL, they may be exposed through error handling paths and captured by logs, diagnostics, or other error consumers. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

En bref

Sévérité
Élevée (CVSS 7.5)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitation active
Non signalée par la CISA
Publication
26 juin 2026
Dernière mise à jour
26 juin 2026

Produits concernés

  • nodejs node.js

Références

Rechercher une autre vulnérabilité dans la base CVE