CVE-2026-106550

Source
https://cve.org/CVERecord?id=CVE-2026-106550
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-106550.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-106550
Published
2026-10-06T20:09:55Z
Modified
2026-10-09T02:30:47Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
CVE-2026-106550
Details

Mozilla's Node-convict (version 6.2.2 and later) is vulnerable to a Denial of Service vulnerability caused by incomplete prototype‑pollution protections in config.set(). An attacker controlling the configuration key can write arbitrary properties to constructor., which walk() resolves to the global Object function. This allows overwriting core JavaScript methods such as Object.assign, leading to persistent process-wide failures and requiring a restart. The issue bypasses existing filters that only block constructor.prototype.* and proto.*. Exploitation requires an endpoint that forwards attacker-controlled keys into config.set().

Database specific
{
    "cna_assigner": "certcc",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/106xxx/CVE-2026-106550.json"
}
References

Affected packages

Git / github.com/mozilla/node-convict

Affected ranges

Type
GIT
Repo
https://github.com/mozilla/node-convict
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "6.2.2"
        },
        {
            "last_affected": "6.2.2"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

6.*
6.2.2
v6.*
v6.2.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-106550.json"