« Volver al listado

CVE-2026-48615

Estado: AnalizadaAlta (7.5)—

A flaw in Node.js proxy tunnel error handling could expose proxy credentials in `ERR_PROXY_TUNNEL` error messages.

When proxy credentials are embedded in the proxy URL, they may be exposed through error handling paths and captured by logs, diagnostics, or other error consumers.

This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

CVE-2026-48615 expone credenciales de proxy en mensajes de error capturables por logs/diagnósticos (T1552.001). AV:N/PR:N/UI:N indica explotación remota sin privilegios (T1190). La exposición inadvertida de credenciales en tránsito sugiere también posible captura por análisis de tráfico (T1040).

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-48615",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-48615",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-06-26T13:34:45.532887Z"
        }
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Secondary",
        "source": "support@hackerone.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 5.9,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.2
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "support@hackerone.com",
      "affectedData": [
        {
          "vendor": "nodejs",
          "product": "node",
          "versions": [
            {
              "status": "affected",
              "version": "22.22.3",
              "versionType": "semver",
              "lessThanOrEqual": "22.22.3"
            },
            {
              "status": "affected",
              "version": "24.16.0",
              "versionType": "semver",
              "lessThanOrEqual": "24.16.0"
            },
            {
              "status": "affected",
              "version": "26.3.0",
              "versionType": "semver",
              "lessThanOrEqual": "26.3.0"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-06-26T02:16:52.273",
  "references": [
    {
      "url": "https://nodejs.org/en/blog/vulnerability/june-2026-security-releases",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "support@hackerone.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "support@hackerone.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-359"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A flaw in Node.js proxy tunnel error handling could expose proxy credentials in `ERR_PROXY_TUNNEL` error messages.\r\n\r\nWhen proxy credentials are embedded in the proxy URL, they may be exposed through error handling paths and captured by logs, diagnostics, or other error consumers.\r\n\r\nThis vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**."
    }
  ],
  "lastModified": "2026-06-26T20:18:50.810",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:nodejs:node.js:22.22.3:*:*:*:-:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3C0C5080-5F99-4651-9855-2DE03C9070C5"
            },
            {
              "criteria": "cpe:2.3:a:nodejs:node.js:24.16.0:*:*:*:-:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3B912C84-1AA5-4D74-AB1A-64162C80A33B"
            },
            {
              "criteria": "cpe:2.3:a:nodejs:node.js:26.3.0:*:*:*:-:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8152ACE6-3CAF-4CA0-8B19-D4753811EB44"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "support@hackerone.com"
}