Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-56850

Опубликовано: 30 июл. 2026
Источник: debian
EPSS Низкий

Описание

A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key collisions, allowing mutual TLS (mTLS) client identities to be reused across requests configured with different client certificates. This vulnerability affects Node.js **26.x**, **24.x**, and **22.x**.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
nodejsfixed24.19.0+dfsg+~cs24.13.3-1package

Примечания

  • https://nodejs.org/en/blog/vulnerability/july-2026-security-releases#https-agent-can-reuse-mtls-identities-across-pfx-certificates-cve-2026-56850---medium

  • Fixed by: https://github.com/nodejs/node/commit/acaf4266b2be7958e3d7cb44b5ee1c2b96eca278 (v22.23.2)

EPSS

Процентиль: 0%
0.00084
Низкий

Связанные уязвимости

CVSS3: 4.4
ubuntu
около 2 месяцев назад

A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key collisions, allowing mutual TLS (mTLS) client identities to be reused across requests configured with different client certificates. This vulnerability affects Node.js **26.x**, **24.x**, and **22.x**.

CVSS3: 4.1
redhat
около 2 месяцев назад

A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key collisions, allowing mutual TLS (mTLS) client identities to be reused across requests configured with different client certificates. This vulnerability affects Node.js **26.x**, **24.x**, and **22.x**.

CVSS3: 4.4
nvd
около 2 месяцев назад

A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key collisions, allowing mutual TLS (mTLS) client identities to be reused across requests configured with different client certificates. This vulnerability affects Node.js **26.x**, **24.x**, and **22.x**.

CVSS3: 4.1
msrc
около 1 месяца назад

A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key collisions, allowing mutual TLS (mTLS) client identities to be reused across requests configured with different client certificates. This vulnerability affects Node.js **26.x**, **24.x**, and **22.x**.

CVSS3: 4.1
github
около 2 месяцев назад

A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key collisions, allowing mutual TLS (mTLS) client identities to be reused across requests configured with different client certificates. This vulnerability affects Node.js **26.x**, **24.x**, and **22.x**.

EPSS

Процентиль: 0%
0.00084
Низкий