Openjs Foundation · Node.Js · CVE-2026-56850
**Name of the Vulnerable Software and Affected Versions**
Node.js versions 22.x
Node.js versions 24.x
Node.js versions 26.x
**Description**
A flaw in the Node.js HTTPS Agent connection reuse mechanism can lead to PFX object-array key collisions. This issue allows mutual TLS (mTLS) client identities to be reused across requests that are configured with different client certificates.
**Recommendations**
Update Node.js version 22.x to the latest patched release.
Update Node.js version 24.x to version 24.18.1-1.1 or newer.
Update Node.js version 26.x to version 26.5.1-1.1 or newer.