CVE-2026-106550None▾ SunlitMozilla's Node-convict (version 6.2.2 and later) is vulnerable to a Denial of Service vulnerability caused by incomplete prototype‑pollution protections in config.set(). An attacker controlling the configuration key can write arbitrary p…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 2.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Mozilla's Node-convict (version 6.2.2 and later) is vulnerable to a Denial of Service vulnerability caused by incomplete prototype‑pollution protections in config.set(). An attacker controlling the configuration key can write arbitrary properties to constructor.<key>, which walk() resolves to the global Object function. This allows overwriting core JavaScript methods such as Object.assign, leading to persistent process-wide failures and requiring a restart. The issue bypasses existing filters that only block constructor.prototype.* and proto.*. Exploitation requires an endpoint that forwards attacker-controlled keys into config.set().
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-103036Medium· 6.5oRPC is a tool that helps build APIs that are end-to-end type-safe and adhere to OpenAPI standards
CVE-2026-103918Medium· 6.5oRPC is a tool that helps build APIs that are end-to-end type-safe and adhere to OpenAPI standards
CVE-2026-104183Medium· 5.1stream-json is a micro-library of stream components for processing JSON and JSONC with a minimal memory footprint
CVE-2026-101909High· 8.3Axios is a promise-based HTTP client for the browser and Node.js
CVE-2026-101904Medium· 6.9Axios is a promise-based HTTP client for the browser and Node.js
CVE-2026-61834Medium· 4.3scim-patch is a library for applying SCIM patch operations