Back to CVE List

CVE-2026-56850

MEDIUM SEVERITY

CVSS Score & Metrics

Base Score
4.1 / 10
Vector String
CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N

Vulnerability Description

A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key collisions, allowing mutual TLS (mTLS) client identities to be reused across requests configured with different client certificates.

This vulnerability affects Node.js **26.x**, **24.x**, and **22.x**.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-287
Source
NVD
Vendor
nodejs
Product
node

External References

Discussion (0)

Add Comment

No comments yet. Be the first!