Node.js HTTPS Agent Vulnerability Affecting Multiple Versions
CVE-2026-56850

4.1MEDIUM

Key Information:

Vendor

Nodejs

Status
Vendor
CVE Published:
30 July 2026

What is CVE-2026-56850?

A flaw in the Node.js HTTPS Agent's handling of connection reuse can lead to PFX object-array key collisions. This issue allows mutual TLS (mTLS) client identities to be improperly reused across different requests that are set up with distinct client certificates, posing a significant risk to the integrity and security of secure communication.

Affected Version(s)

node 26.5.0

node 24.18.0

node 22.23.1

References

CVSS V3.0

Score:
4.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.