CVE-2026-56850

Aliases:ALPINE-CVE-2026-56850UBUNTU-CVE-2026-56850DEBIAN-CVE-2026-56850CGA-2g4f-xcr5-37pqCGA-8ppq-5q9m-37vcCGA-9jh2-j73w-g296CGA-h26j-6v9m-hpgrCGA-qpvq-5fx6-qjf7CGA-rpf3-j36v-rw9jCGA-rrm6-mjxg-9f75CGA-vfmr-jcpp-5jr9
Analyzed
Published: 30 Jul 2026, 06:02
Last modified:30 Jul 2026, 12:37

Vulnerability Summary

Overall Risk (default)
low
18/100
CVSS Score
4.4 MEDIUM
v3.1 (nvd)
EPSS Score
0.08% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

30 Jul 2026, 06:02
Published
Vulnerability first disclosed
30 Jul 2026, 12:37
Last Modified
Vulnerability information updated

Description

A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key collisions, allowing mutual TLS (mTLS) client identities to be reused across requests configured with different client certificates. This vulnerability affects Node.js **26.x**, **24.x**, and **22.x**.

CVSS Metrics

  • v3.1MEDIUMScore: 4.4CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
  • v3.0MEDIUMScore: 4.1CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N

EPSS Trends

Current EPSS score: 0.08% Percentile: 0%

Techniques & Countermeasures

  • CWE-287Improper Authentication

    When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Systems

  • alpinenodejs

    < 22.23.2-r0 | < 22.23.2-r0 | < 24.18.1-r0 | < 24.18.1-r0

  • chainguardnodejs-20

    all

  • chainguardnodejs-22

    < 22.23.2-r0

  • chainguardnodejs-24

    < 24.19.0-r0

  • chainguardnodejs-25

    all

  • wolfinodejs-20

    all

  • wolfinodejs-22

    < 22.23.2-r0

  • wolfinodejs-24

    < 24.19.0-r0

  • wolfinodejs-25

    all

  • debiannodejs

    all | all | all | all | < 24.19.0+dfsg+~cs24.13.3-1

  • ubuntunodejs

    all | all | all

  • nodejsnode

    26.5.0 | 24.18.0 | 22.23.1

  • nodejsnode.js

    ≥ 22.0, ≤ 22.23.1 | ≥ 24.0.0, ≤ 24.18.0 | ≥ 26.0.0, ≤ 26.5.0

References (8)