SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-56850

MEDIUM · CVSS 4.4 EPSS 0.08%

Source: NVD + CISA KEV + EPSS · Published 2026-07-30 · Last synced 2026-08-29

CyberRota Analysis

AI-Generated

A flaw in Node.js's HTTPS Agent connection reuse can lead to PFX object-array key collisions, which may result in mutual TLS (mTLS) client identities being incorrectly reused across requests that are configured with different client certificates. This could potentially compromise the security of applications relying on mTLS for authentication. Organizations using Node.js versions 22.x, 24.x, or 26.x should prioritize addressing this vulnerability to safeguard their systems against unauthorized access.

CVE
CVE-2026-56850
Severity
MEDIUM
CVSS
4.4
EPSS
0.08%

Original NVD Description

A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key collisions, allowing mutual TLS (mTLS) client identities to be reused across requests configured with different client certificates. This vulnerability affects Node.js **26.x**, **24.x**, and **22.x**.

Related CVEs

Other vulnerabilities affecting the same vendor(s)