Node.js proxy tunnel error message credential leak
CVE-2026-48615 is a medium-severity information disclosure vulnerability in Node.js affecting proxy tunnel error handling. When Node.js encounters an ERR_PROXY_TUNNEL condition while using an HTTP proxy tunnel, proxy credentials embedded in the proxy URL may be included in the generated error message. As a result, usernames, passwords, or other proxy authentication material can be exposed through logs, diagnostic output, exception traces, or other error-reporting channels. The issue affects the supported Node.js 22.x, 24.x, and 26.x release lines.
Are you exposed to this one?
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
Impact, mitigation & remediation
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
Impact
What an attacker gets, and what they’ve been doing with it.
ERR_PROXY_TUNNEL messages, attackers or unauthorized users with access to logs, monitoring systems, crash reports, or application output may recover proxy authentication secrets. This can enable subsequent unauthorized use of the proxy service and potentially facilitate further access depending on how those credentials are reused.Mitigation
If you can’t patch tonight, do this now.
ERR_PROXY_TUNNEL and related exception output before logging or returning it to users. Restrict access to application logs, diagnostics, and crash-reporting systems that may contain historical error messages. Rotate exposed proxy credentials if leakage is suspected.Remediation
Patch, then assume compromise.
Exploits
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Recent activity
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A medium-severity Node.js information disclosure flaw that can leak proxy credentials through ERR_PROXY_TUNNEL error messages.
A medium-severity Node.js flaw that leaks sensitive proxy credentials in error messages.
The version that knows your environment.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.