Exposure of Private Personal Information to an Unauthorized Actor Affecting nodejs package, versions [22.20.0,]


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.39% (32nd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-CONAN-NODEJS-17674626
  • published29 Jun 2026
  • disclosed26 Jun 2026
  • creditnssys

Introduced: 26 Jun 2026

NewCVE-2026-48615  (opens in a new tab)
CWE-359  (opens in a new tab)

How to fix?

A fix was pushed into the master branch but not yet published.

Overview

Affected versions of this package are vulnerable to Exposure of Private Personal Information to an Unauthorized Actor in the ProxyConfig constructor in lib/internal/http.js, which stores the full proxy URL including any embedded username and password and surfaces it in ERR_PROXY_TUNNEL error messages. When proxy tunnel establishment fails, the resulting error carries the credentials embedded in the proxy URL, exposing them to anyone able to read the process's error output, stack traces, logs, or diagnostics. Exposure requires the proxy to be configured with credentials embedded in its URL and occurs only on a tunnel establishment failure, reaching only parties with access to that error output or downstream log and diagnostic sinks.

CVSS Base Scores

version 4.0
version 3.1