PT-2026-52057 · Openjs Foundation+1 · Node.Js+1
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Node.js versions 22.x
Node.js versions 24.x
Node.js versions 26.0.0 through 26.3.0
Description
An issue in proxy tunnel error handling may lead to the exposure of proxy credentials within
ERR PROXY TUNNEL error messages. This occurs when credentials are embedded in the proxy URL, allowing them to be captured by logs, diagnostics, or other error consumers through specific error handling paths.Recommendations
Update Node.js 22.x to the latest security release.
Update Node.js 24.x to the latest security release.
Update Node.js 26.x to version 26.3.1 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Node.Js
Rocky Linux