{"id":"CVE-2026-106550","title":"Mozilla's Node-convict (version 6.2.2 and later) is vulnerable to a Denial of Service vulnerability caused by incomplete prototype‑pollution protections in config.set()","summary":"Mozilla's Node-convict (version 6.2.2 and later) is vulnerable to a Denial of Service vulnerability caused by incomplete prototype‑pollution protections in config.set(). An attacker controlling the configuration key can write arbitrary p…","severity":"none","cwe":["CWE-1321","CWE-915","CWE-400"],"vendor":"Mozilla","product":"Node-convict","affected":["Node-convict 6.2.2"],"published":"2026-10-06","updated":"2026-10-06","sourceUpdated":"2026-10-06T21:17:18.810","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-106550","references":[{"url":"https://github.com/mozilla/node-convict","label":"cret@cert.org"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-06T21:20:28.986Z","slug":"CVE-2026-106550","body":"## Overview\n\nMozilla's Node-convict (version 6.2.2 and later) is vulnerable to a Denial of Service vulnerability caused by incomplete prototype‑pollution protections in config.set(). An attacker controlling the configuration key can write arbitrary properties to constructor.<key>, which walk() resolves to the global Object function. This allows overwriting core JavaScript methods such as Object.assign, leading to persistent process-wide failures and requiring a restart. The issue bypasses existing filters that only block constructor.prototype.* and __proto__.*. Exploitation requires an endpoint that forwards attacker-controlled keys into config.set().\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}