Mozilla's Node-convict (version 6.2.2 and later) is vulnerable to a Denial of Service vulnerability caused by incomplete prototype‑pollution protections in config.set(). An attacker controlling the configuration key can write arbitrary properties to constructor.<key>, which walk() resolves to the global Object function. This allows overwriting core JavaScript methods such as Object.assign, leading to persistent process-wide failures and requiring a restart. The issue bypasses existing filters that only block constructor.prototype.* and __proto__.*. Exploitation requires an endpoint that forwards attacker-controlled keys into config.set().
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://github.com/mozilla/node-convict |
|
History
Tue, 06 Oct 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mozilla's Node-convict (version 6.2.2 and later) is vulnerable to a Denial of Service vulnerability caused by incomplete prototype‑pollution protections in config.set(). An attacker controlling the configuration key can write arbitrary properties to constructor.<key>, which walk() resolves to the global Object function. This allows overwriting core JavaScript methods such as Object.assign, leading to persistent process-wide failures and requiring a restart. The issue bypasses existing filters that only block constructor.prototype.* and __proto__.*. Exploitation requires an endpoint that forwards attacker-controlled keys into config.set(). | |
| Title | CVE-2026-106550 | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: certcc
Published:
Updated: 2026-10-06T20:09:55.919Z
Reserved: 2026-10-06T20:07:46.075Z
Link: CVE-2026-106550
No data.
Status : Received
Published: 2026-10-06T21:17:18.810
Modified: 2026-10-06T21:17:18.810
Link: CVE-2026-106550
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.