Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qqjm-7pv6-7q82

Опубликовано: 26 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 5.9

Описание

A flaw in Node.js proxy tunnel error handling could expose proxy credentials in ERR_PROXY_TUNNEL error messages.

When proxy credentials are embedded in the proxy URL, they may be exposed through error handling paths and captured by logs, diagnostics, or other error consumers.

This vulnerability affects all supported release lines: Node.js 22, Node.js 24, and Node.js 26.

A flaw in Node.js proxy tunnel error handling could expose proxy credentials in ERR_PROXY_TUNNEL error messages.

When proxy credentials are embedded in the proxy URL, they may be exposed through error handling paths and captured by logs, diagnostics, or other error consumers.

This vulnerability affects all supported release lines: Node.js 22, Node.js 24, and Node.js 26.

EPSS

Процентиль: 36%
0.00437
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-359

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 1 месяца назад

[Unknown description]

CVSS3: 5.9
redhat
около 1 месяца назад

A flaw in Node.js proxy tunnel error handling could expose proxy credentials in `ERR_PROXY_TUNNEL` error messages. When proxy credentials are embedded in the proxy URL, they may be exposed through error handling paths and captured by logs, diagnostics, or other error consumers. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

CVSS3: 7.5
nvd
около 1 месяца назад

A flaw in Node.js proxy tunnel error handling could expose proxy credentials in `ERR_PROXY_TUNNEL` error messages. When proxy credentials are embedded in the proxy URL, they may be exposed through error handling paths and captured by logs, diagnostics, or other error consumers. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

CVSS3: 7.5
debian
около 1 месяца назад

A flaw in Node.js proxy tunnel error handling could expose proxy crede ...

suse-cvrf
около 1 месяца назад

Security update for nodejs22

EPSS

Процентиль: 36%
0.00437
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-359