Описание
A flaw in Node.js proxy tunnel error handling could expose proxy credentials in ERR_PROXY_TUNNEL error messages.
When proxy credentials are embedded in the proxy URL, they may be exposed through error handling paths and captured by logs, diagnostics, or other error consumers.
This vulnerability affects all supported release lines: Node.js 22, Node.js 24, and Node.js 26.
A flaw was found in Node.js. When proxy credentials are embedded in a proxy URL, an issue in the proxy tunnel error handling can lead to the exposure of these credentials. This information disclosure vulnerability allows an attacker to potentially capture sensitive proxy credentials through logs, diagnostics, or other error-consuming mechanisms.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 8 | nodejs:22/nodejs | Affected | ||
| Red Hat Enterprise Linux 8 | nodejs:24/nodejs | Affected | ||
| Red Hat Enterprise Linux 10 | nodejs24 | Fixed | RHSA-2026:35841 | 06.07.2026 |
| Red Hat Enterprise Linux 10 | nodejs22 | Fixed | RHSA-2026:35842 | 06.07.2026 |
| Red Hat Enterprise Linux 9 | nodejs | Fixed | RHSA-2026:35891 | 06.07.2026 |
| Red Hat Enterprise Linux 9 | nodejs | Fixed | RHSA-2026:35892 | 06.07.2026 |
| Red Hat Hardened Images | nodejs22-main-22.23.1-1.hum1 | Fixed | RHSA-2026:28727 | 24.06.2026 |
| Red Hat Hardened Images | nodejs24-main-24.18.0-0.1.hum1 | Fixed | RHSA-2026:29012 | 24.06.2026 |
| Red Hat Hardened Images | nodejs26-main-26.4.0-1.2.hum1 | Fixed | RHSA-2026:30172 | 25.06.2026 |
| Red Hat Hardened Images | nodejs25-main-25.9.0-1.1.hum1 | Fixed | RHSA-2026:7378 | 10.04.2026 |
Показывать по
Дополнительная информация
Статус:
5.9 Medium
CVSS3
Связанные уязвимости
A flaw in Node.js proxy tunnel error handling could expose proxy credentials in `ERR_PROXY_TUNNEL` error messages. When proxy credentials are embedded in the proxy URL, they may be exposed through error handling paths and captured by logs, diagnostics, or other error consumers. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.
A flaw in Node.js proxy tunnel error handling could expose proxy credentials in `ERR_PROXY_TUNNEL` error messages. When proxy credentials are embedded in the proxy URL, they may be exposed through error handling paths and captured by logs, diagnostics, or other error consumers. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.
A flaw in Node.js proxy tunnel error handling could expose proxy crede ...
A flaw in Node.js proxy tunnel error handling could expose proxy credentials in `ERR_PROXY_TUNNEL` error messages. When proxy credentials are embedded in the proxy URL, they may be exposed through error handling paths and captured by logs, diagnostics, or other error consumers. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.
5.9 Medium
CVSS3