Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qqjm-7pv6-7q82

Опубликовано: 26 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 5.9

Описание

A flaw in Node.js proxy tunnel error handling could expose proxy credentials in ERR_PROXY_TUNNEL error messages.

When proxy credentials are embedded in the proxy URL, they may be exposed through error handling paths and captured by logs, diagnostics, or other error consumers.

This vulnerability affects all supported release lines: Node.js 22, Node.js 24, and Node.js 26.

A flaw in Node.js proxy tunnel error handling could expose proxy credentials in ERR_PROXY_TUNNEL error messages.

When proxy credentials are embedded in the proxy URL, they may be exposed through error handling paths and captured by logs, diagnostics, or other error consumers.

This vulnerability affects all supported release lines: Node.js 22, Node.js 24, and Node.js 26.

EPSS

Процентиль: 36%
0.00421
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-359

Связанные уязвимости

CVSS3: 7.5
ubuntu
3 месяца назад

A flaw in Node.js proxy tunnel error handling could expose proxy credentials in `ERR_PROXY_TUNNEL` error messages. When proxy credentials are embedded in the proxy URL, they may be exposed through error handling paths and captured by logs, diagnostics, or other error consumers. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

CVSS3: 5.9
redhat
3 месяца назад

A flaw in Node.js proxy tunnel error handling could expose proxy credentials in `ERR_PROXY_TUNNEL` error messages. When proxy credentials are embedded in the proxy URL, they may be exposed through error handling paths and captured by logs, diagnostics, or other error consumers. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

CVSS3: 7.5
nvd
3 месяца назад

A flaw in Node.js proxy tunnel error handling could expose proxy credentials in `ERR_PROXY_TUNNEL` error messages. When proxy credentials are embedded in the proxy URL, they may be exposed through error handling paths and captured by logs, diagnostics, or other error consumers. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

CVSS3: 7.5
debian
3 месяца назад

A flaw in Node.js proxy tunnel error handling could expose proxy crede ...

rocky
около 2 месяцев назад

Important: nodejs:22 security, bug fix, and enhancement update

EPSS

Процентиль: 36%
0.00421
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-359