search
Node-convict
Trends
- 1Mozilla's Node-convict hit by denial-of-service flawโ๐จ EUVD-2026-93988 ๐ Score: n/a ๐ฆ Product: Node-convict ๐ข Vendor: Mozilla ๐ Updated: 2026-10-06 ๐ Mozilla's Node-convict
A vulnerability tracked as EUVD-2026-93988 has been published for Mozilla's Node-convict library, affecting versions 6.2.2 and later. The flaw stems from incomplete prototype-pollution protections in the config.set() function, potentially allowing attackers to trigger a denial of service. No severity score has been assigned yet. Developers using Node-convict in production are advised to monitor for an updated release and review their dependency trees.