VYPR
Medium severity4.4NVD Advisory· Published Jul 30, 2026· Updated Aug 25, 2026

CVE-2026-56850

CVE-2026-56850

Description

A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key collisions, allowing mutual TLS (mTLS) client identities to be reused across requests configured with different client certificates.

This vulnerability affects Node.js 26.x, 24.x, and 22.x.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

11

Patches

Vulnerability mechanics

References

1

News mentions

2