Inclusion of Sensitive Information in Log Files in Node.js - CVE-2026-48615
Published: June 22, 2026
Node.js
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper handling of sensitive information in ERR_PROXY_TUNNEL error messages when processing proxy URLs with embedded credentials. A remote user can trigger an error handling path to disclose sensitive information.
The exposed data may be captured by logs, diagnostics, or other error consumers.