Node.js HTTPS Agent PFX Key Collision Enables mTLS Identity Reuse
CVE-2026-56850 Published on July 30, 2026

A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key collisions, allowing mutual TLS (mTLS) client identities to be reused across requests configured with different client certificates. This vulnerability affects Node.js **26.x**, **24.x**, and **22.x**.

NVD

Weakness Type

What is an authentification Vulnerability?

When an actor claims to have a given identity, the software does not prove or insufficiently proves that the claim is correct.

CVE-2026-56850 has been classified to as an authentification vulnerability or weakness.


Affected Versions

nodejs node: