A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key collisions, allowing mutual TLS (mTLS) client identities to be reused… (CVE-2026-56850)
A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key collisions, allowing mutual TLS (mTLS) client identities to be reused across requests configured with different client certificates. This vulnerability affects Node.js **26.x**, **24.x**, and **22.x**.
AI Analysis
Technical Summary
The Red Hat security advisory RHSA-2026:48273 details updates to Red Hat Hardened Images RPMs, including Node.js 26 packages, to fix multiple vulnerabilities such as CVE-2026-56850 and CVE-2026-58043. CVE-2026-58043 is a flaw in Node.js's permission model enforcement when the --permission flag is active, allowing attackers with limited file system access to bypass authorization controls and access unauthorized files or directories. The advisory lists updated RPM versions for nodejs26 and related packages. Red Hat has released these updates to address the vulnerabilities, but no explicit patch links or detailed remediation instructions are provided beyond the advisory references. No exploits are known to be active in the wild.
Potential Impact
The primary impact is unauthorized file system access due to improper enforcement of permission controls in Node.js, potentially leading to unauthorized information disclosure and data modification. The vulnerabilities affect Red Hat Hardened Images and Node.js packages on aarch64 and x86_64 architectures. The severity is assessed as medium (moderate), reflecting the potential for privilege escalation or unauthorized access but with conditions such as requiring local access and high attack complexity.
Mitigation Recommendations
Red Hat has released updated RPM packages for Node.js 26 and related components as part of the Red Hat Hardened Images update. Users should apply these official updates to remediate the vulnerabilities. No alternative mitigations or workarounds are explicitly stated in the advisory. Patch status is confirmed by the availability of updated RPMs in the advisory. Users should follow Red Hat's official guidance at https://images.redhat.com/ and https://access.redhat.com/security/updates/classification/ for applying updates.
A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key collisions, allowing mutual TLS (mTLS) client identities to be reused… (CVE-2026-56850)
Description
A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key collisions, allowing mutual TLS (mTLS) client identities to be reused across requests configured with different client certificates. This vulnerability affects Node.js **26.x**, **24.x**, and **22.x**.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Red Hat security advisory RHSA-2026:48273 details updates to Red Hat Hardened Images RPMs, including Node.js 26 packages, to fix multiple vulnerabilities such as CVE-2026-56850 and CVE-2026-58043. CVE-2026-58043 is a flaw in Node.js's permission model enforcement when the --permission flag is active, allowing attackers with limited file system access to bypass authorization controls and access unauthorized files or directories. The advisory lists updated RPM versions for nodejs26 and related packages. Red Hat has released these updates to address the vulnerabilities, but no explicit patch links or detailed remediation instructions are provided beyond the advisory references. No exploits are known to be active in the wild.
Potential Impact
The primary impact is unauthorized file system access due to improper enforcement of permission controls in Node.js, potentially leading to unauthorized information disclosure and data modification. The vulnerabilities affect Red Hat Hardened Images and Node.js packages on aarch64 and x86_64 architectures. The severity is assessed as medium (moderate), reflecting the potential for privilege escalation or unauthorized access but with conditions such as requiring local access and high attack complexity.
Mitigation Recommendations
Red Hat has released updated RPM packages for Node.js 26 and related components as part of the Red Hat Hardened Images update. Users should apply these official updates to remediate the vulnerabilities. No alternative mitigations or workarounds are explicitly stated in the advisory. Patch status is confirmed by the availability of updated RPMs in the advisory. Users should follow Red Hat's official guidance at https://images.redhat.com/ and https://access.redhat.com/security/updates/classification/ for applying updates.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-777r-4cwx-g26v
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-56850"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.0
Threat ID: 6a6b72c89c2644c7f8475e2a
Added to database: 07/30/2026, 15:50:32 UTC
Last enriched: 08/06/2026, 22:49:10 UTC
Last updated: 09/14/2026, 22:01:35 UTC
Views: 128
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.