CVE-2026-56850
Node.js Analyse et atténuation des vulnérabilités

Aperçu

CVE-2026-56850 is a Medium-severity improper authentication vulnerability in Node.js titled "HTTPS Agent can reuse mTLS identities across PFX certificates." A flaw in the Node.js HTTPS Agent connection reuse logic causes PFX object-array key collisions, allowing mutual TLS (mTLS) client identities to be incorrectly reused across requests that are configured with different client certificates. The vulnerability affects Node.js 26.x (up to and including 26.5.0), 24.x (up to and including 24.18.0), and 22.x (up to and including 22.23.1). It was reported by researcher "yottt" via HackerOne and publicly disclosed on July 30, 2026, with patched releases made available the same day. The CVSS v3.0 base score is 4.1 (Medium), assigned by HackerOne (Node.js Advisory, GitHub Advisory).

Détails techniques

The root cause is classified as CWE-287 (Improper Authentication). The flaw resides in the Node.js HTTPS Agent's connection reuse mechanism, where PFX (PKCS#12) certificate objects are keyed in an internal array using a key that can collide when different PFX configurations are used. This collision causes the agent to associate an already-established mTLS connection — authenticated with one client certificate — with a new request that specifies a different client certificate, effectively reusing the wrong client identity. Exploitation requires local access with high privileges (e.g., administrative access to the Node.js process or system), and the attack complexity is rated High, limiting practical exploitability. The fix was implemented by maintainer RafaelGSS (Node.js Advisory, GitHub Advisory).

Impact

The primary impact is on integrity: a high-privilege local attacker can cause mTLS client certificates to be reused incorrectly across different outbound HTTPS requests, meaning a request intended to authenticate with one client identity may instead authenticate using a different client's certificate. This could allow unauthorized actions to be performed on a remote server under a different client's identity, potentially bypassing access controls in mTLS-protected service-to-service communication. There is no confidentiality or availability impact associated with this vulnerability (Node.js Advisory, GitHub Advisory).

Atténuation et solutions de contournement

Node.js has released patched versions addressing this vulnerability: v22.23.2, v24.18.1, and v26.5.1. Users should upgrade to the appropriate patched release for their release line as soon as possible. As interim mitigations, administrators should review and monitor mTLS certificate configurations in Node.js applications to ensure proper certificate binding per request, and consider implementing additional server-side certificate validation to detect unexpected certificate mismatches (Node.js Advisory, Node.js v22.23.2, Node.js v24.18.1, Node.js v26.5.1).

Réactions de la communauté

The vulnerability was part of a broader July 2026 Node.js security release that addressed 11 security flaws across active release lines, which received coverage from cybersecurity news outlets including CyberSecurityNews and CyberPress. The Node.js project credited researcher "yottt" for the report and maintainer RafaelGSS for the fix. Community attention was primarily focused on the higher-severity HTTP/2 and Permission Model issues in the same release batch (Node.js Advisory, CyberSecurityNews).

Ressources additionnelles


SourceCe rapport a été généré à l’aide de l’IA

Apparenté Node.js Vulnérabilités:

Identifiant CVE

Sévérité

Score

Technologies

Nom du composant

Exploit CISA KEV

A corrigé

Date de publication

CVE-2026-54272MEDIUM6.9
  • Node.js logoNode.js
  • rust-std-static-wasm32-unknown-unknown
NonNonJul 27, 2026
CVE-2026-58043NONEN/A
  • Node.js logoNode.js
  • nodejs
NonOuiJul 30, 2026
CVE-2026-58040NONEN/A
  • Node.js logoNode.js
  • nodejs
NonOuiJul 30, 2026
CVE-2026-56850NONEN/A
  • Node.js logoNode.js
  • nodejs
NonOuiJul 30, 2026
CVE-2026-56847NONEN/A
  • Node.js logoNode.js
  • nodejs
NonOuiJul 30, 2026

Évaluation gratuite des vulnérabilités

Évaluez votre posture de sécurité dans le cloud

Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.

Demander une évaluation

Obtenez une démo personnalisée

Prêt(e) à voir Wiz en action ?

"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
David EstlickRSSI
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
Adam FletcherChef du service de sécurité
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."
Greg PoniatowskiResponsable de la gestion des menaces et des vulnérabilités