Node.js HTTPS Agent Vulnerability Affecting Multiple Versions
CVE-2026-56850
4.1MEDIUM
What is CVE-2026-56850?
A flaw in the Node.js HTTPS Agent's handling of connection reuse can lead to PFX object-array key collisions. This issue allows mutual TLS (mTLS) client identities to be improperly reused across different requests that are set up with distinct client certificates, posing a significant risk to the integrity and security of secure communication.
Affected Version(s)
node 26.5.0
node 24.18.0
node 22.23.1
