---
id: CVE-2022-0235
title: >-
  node-fetch is vulnerable to Exposure of Sensitive Information to an
  Unauthorized Actor
summary: >-
  node-fetch is vulnerable to Exposure of Sensitive Information to an
  Unauthorized Actor
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-200
  - CWE-601
vendor: node-fetch_project
product: node-fetch
affected:
  - node-fetch < 2.6.7
  - 'node-fetch >= 3.0.0, < 3.1.1'
  - sinec_ins < 1.0
  - sinec_ins = 1.0
  - debian_linux = 10.0
patched:
  - node-fetch 3.1.1
  - sinec_ins 1.0
published: '2022-01-16'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T18:17:11.073'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2022-0235'
references:
  - url: 'https://cert-portal.siemens.com/productcert/pdf/ssa-637483.pdf'
    label: security@huntr.dev
  - url: >-
      https://github.com/node-fetch/node-fetch/commit/36e47e8a6406185921e4985dcbeff140d73eaa10
    label: security@huntr.dev
  - url: 'https://huntr.dev/bounties/d26ab655-38d6-48b3-be15-f9ad6b6ae6f7'
    label: security@huntr.dev
  - url: 'https://lists.debian.org/debian-lts-announce/2022/12/msg00007.html'
    label: security@huntr.dev
  - url: 'https://cert-portal.siemens.com/productcert/pdf/ssa-637483.pdf'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://github.com/node-fetch/node-fetch/commit/36e47e8a6406185921e4985dcbeff140d73eaa10
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://huntr.dev/bounties/d26ab655-38d6-48b3-be15-f9ad6b6ae6f7'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2022/12/msg00007.html'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - cve.org
  - score-dispute
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-10-07T17:50:13.834950Z'
scores:
  nvd: 6.1
  cna: 8.8
epss: 0.01653
epssPercentile: 0.75818
ingestedAt: '2026-10-07T18:42:20.874Z'
---

## Overview

node-fetch is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor

## Affected

- `node-fetch < 2.6.7`
- `node-fetch >= 3.0.0, < 3.1.1`
- `sinec_ins < 1.0`
- `sinec_ins = 1.0`
- `debian_linux = 10.0`

## Remediation

Upgrade past the affected range:

- `node-fetch 3.1.1`
- `sinec_ins 1.0`
