]> dgit.raspbian.org Git - nodejs.git/commit
https: distinguish PFX object-array agent keys
authorRafaelGSS <rafael.nunu@hotmail.com>
Mon, 20 Jul 2026 16:15:10 +0000 (13:15 -0300)
committerBastien Roucariès <rouca@debian.org>
Sun, 16 Aug 2026 17:34:06 +0000 (19:34 +0200)
commitcc6967f7ff785a9d69ec6d3bd0c777288f6f9164
tree92146a4fa11976c1b60460464b2ff712e0bdd611
parent4fcec73db4a0d753f435fe9fdacc8372b1be54a5
https: distinguish PFX object-array agent keys

Signed-off-by: RafaelGSS <rafael.nunu@hotmail.com>
PR-URL: https://github.com/nodejs-private/node-private/pull/930
Refs: https://hackerone.com/reports/3816840
CVE-ID: CVE-2026-56850
bug: https://nodejs.org/en/blog/vulnerability/july-2026-security-releases#https-agent-can-reuse-mtls-identities-across-pfx-certificates-cve-2026-56850---medium
origin: https://github.com/nodejs/node/commit/acaf4266b2be7958e3d7cb44b5ee1c2b96eca278

Gbp-Pq: Topic sec
Gbp-Pq: Name CVE-2026-56850.patch
lib/https.js
test/parallel/test-https-agent-getname.js
test/parallel/test-https-agent-pfx-object-array-reuse.js [new file with mode: 0644]