GHSA-777r-4cwx-g26vMediumCVSS 4.1

A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key collisions,...

Published
July 30, 2026
Last Modified
July 30, 2026

🔗 CVE IDs covered (1)

📋 Description

A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key collisions, allowing mutual TLS (mTLS) client identities to be reused across requests configured with different client certificates.

This vulnerability affects Node.js 26.x, 24.x, and 22.x.

🔗 References (3)