Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-56850

Опубликовано: 30 июл. 2026
Источник: redhat
CVSS3: 4.1
EPSS Низкий

Описание

A flaw was found in Node.js. The HTTPS Agent, responsible for managing secure connections, can incorrectly reuse client identities across different requests. This occurs due to a technical issue with PFX object-array key collisions during connection reuse. As a result, a client's identity, established through mutual TLS (mTLS) authentication, could be mistakenly applied to another request, potentially leading to unauthorized access or identity spoofing.

Отчет

This Moderate flaw in Node.js allows mutual TLS (mTLS) client identities to be reused across requests due to a connection reuse issue within the HTTPS Agent. This can lead to unintended identity confusion if applications are configured to use different client certificates with reused connections, potentially enabling unauthorized access within the mTLS context.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10nodejs22Fix deferred
Red Hat Enterprise Linux 10nodejs24Fix deferred
Red Hat Enterprise Linux 8nodejs:22/nodejsFix deferred
Red Hat Enterprise Linux 8nodejs:24/nodejsFix deferred
Red Hat Enterprise Linux 9nodejs:22/nodejsFix deferred
Red Hat Enterprise Linux 9nodejs:24/nodejsFix deferred
Red Hat Hardened Imagesnodejs20Fix deferred
Red Hat Hardened Imagesnodejs25Fix deferred
Red Hat Hardened Imagesnodejs26-main-26.5.1-1.5.hum1FixedRHSA-2026:4827329.07.2026
Red Hat Hardened Imagesnodejs22-main-22.23.2-2.3.hum1FixedRHSA-2026:4830529.07.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-303
https://bugzilla.redhat.com/show_bug.cgi?id=2509179nodejs: Node.js: mTLS client identities can be reused due to HTTPS Agent connection flaw

EPSS

Процентиль: 0%
0.00079
Низкий

4.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.1
ubuntu
4 дня назад

A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key collisions, allowing mutual TLS (mTLS) client identities to be reused across requests configured with different client certificates. This vulnerability affects Node.js **26.x**, **24.x**, and **22.x**.

CVSS3: 4.1
nvd
5 дней назад

A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key collisions, allowing mutual TLS (mTLS) client identities to be reused across requests configured with different client certificates. This vulnerability affects Node.js **26.x**, **24.x**, and **22.x**.

CVSS3: 4.1
debian
5 дней назад

A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-ar ...

CVSS3: 4.1
github
5 дней назад

A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key collisions, allowing mutual TLS (mTLS) client identities to be reused across requests configured with different client certificates. This vulnerability affects Node.js **26.x**, **24.x**, and **22.x**.

EPSS

Процентиль: 0%
0.00079
Низкий

4.1 Medium

CVSS3