Node.js HTTPS Agent PFX Key Collision Enables mTLS Identity Reuse
CVE-2026-56850 Published on July 30, 2026
A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key collisions, allowing mutual TLS (mTLS) client identities to be reused across requests configured with different client certificates. This vulnerability affects Node.js **26.x**, **24.x**, and **22.x**.
Weakness Type
What is an authentification Vulnerability?
When an actor claims to have a given identity, the software does not prove or insufficiently proves that the claim is correct.
CVE-2026-56850 has been classified to as an authentification vulnerability or weakness.
Affected Versions
nodejs node:- Version 26.5.0, <= 26.5.0 is affected.
- Version 24.18.0, <= 24.18.0 is affected.
- Version 22.23.1, <= 22.23.1 is affected.