PT-2026-52057 · Openjs Foundation+1 · Node.Js+1

·

CVE-2026-48615

·

Published

2026-06-19

·

Updated

2026-09-03

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Node.js versions 22.x Node.js versions 24.x Node.js versions 26.0.0 through 26.3.0
Description An issue in proxy tunnel error handling may lead to the exposure of proxy credentials within ERR PROXY TUNNEL error messages. This occurs when credentials are embedded in the proxy URL, allowing them to be captured by logs, diagnostics, or other error consumers through specific error handling paths.
Recommendations Update Node.js 22.x to the latest security release. Update Node.js 24.x to the latest security release. Update Node.js 26.x to version 26.3.1 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:35841
ALSA-2026:35842
ALSA-2026:35891
ALSA-2026:35892
ALSA-2026:39868
ALSA-2026:41947
AZL-91230
BIT-NODE-2026-48615
BIT-NODE-MIN-2026-48615
CVE-2026-48615
ECHO-117A-9A28-6844
OPENSUSE-SU-2026:11110-1
OPENSUSE-SU-2026:11121-1
OPENSUSE-SU-2026:21058-1
OPENSUSE-SU-2026:21236-1
RHSA-2026:28727
RHSA-2026:29012
RHSA-2026:30172
RHSA-2026:35841
RHSA-2026:35842
RHSA-2026:35891
RHSA-2026:35892
RHSA-2026:39868
RHSA-2026:52399
RHSA-2026:7378
RHSA-2026:9455
SUSE-SU-2026:22368-1
SUSE-SU-2026:22565-1
SUSE-SU-2026:2633-1
SUSE-SU-2026:2647-1
SUSE-SU-2026:2695-1
SUSE-SU-2026:3929-1
SUSE-SU-2026:3930-1

Affected Products

Node.Js
Rocky Linux