node is vulnerable to Hostname Verification Bypass. When multiple connections to the same server are opened, TLS sessions from client side can be reused, leading to a bypass of verification of host certificate and allowing an authorized connection with the cached session ticket.
github.com/nodejs/node/blob/b1d4c13430c92e94920f0c8c9ba1295c075c9e89/lib/https.js#L130
github.com/nodejs/node/commit/0932309af2d9d66611cf5387f2cc925a80cb441f
github.com/nodejs/node/commit/94571c100131bda7d8780d2b789feecb98ef65d6
hackerone.com/reports/811502
hackerone.com/reports/811502
nodejs.org/en/blog/vulnerability/june-2020-security-releases/
security.gentoo.org/glsa/202101-07
security.netapp.com/advisory/ntap-20200625-0002/
www.oracle.com//security-alerts/cpujul2021.html
www.oracle.com/security-alerts/cpuapr2022.html
www.oracle.com/security-alerts/cpujan2021.html
www.oracle.com/security-alerts/cpujul2020.html
www.oracle.com/security-alerts/cpuoct2020.html