CVE-2026-33864Disclosure

LOW

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

0.5/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-03-30)
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-27: 1Mentions · 2026-03-30: 2Patch / Workaround · 2026-03-30: 1Technical Details · 2026-03-27: 1Technical Details · 2026-03-30: 203-2703-30
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-03-271
Disclosure1
2026-03-302
Disclosure1Patch1
Full discourse3 posts
  • Gray Hats@the_yellow_fall
    Patch

    Node-convict (CVE-2026-33864) faces a 9.4 CVSS Prototype Pollution flaw. Bypass filters and hijack Node.js apps. Update to version 6.2.5 now to stay secure. #NodeJS #CyberSecurity #PrototypePollution #InfoSec #Vulnerability #Javascript #WebDev #PatchAlert https://securityonline.info/node-convict-prototype-pollution-vulnerability-cve-2026-33864/ https://t.co/FVUhMzWJel

    Post summary

    The tweet announces a critical prototype‑pollution flaw (CVE‑2026‑33864) affecting Node‑convict and urges users to upgrade to version 6.2.5 for remediation.

    040132755
    12.3K followersView on X
  • CrowdCyber 🌐@CrowdCyber_Com
    Disclosure

    The Weakest Link: Popular Node.js Config Library “Convict” Hit by Prototype Pollution https://securityonline.info/node-convict-prototype-pollution-vulnerability-cve-2026-33864/

    Post summary

    The article announces a prototype‑pollution vulnerability (CVE-2026-33864) in the Node.js library Convict, but does not provide PoC, exploit, or patch details.

    0000049
    242 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    A CRITICAL prototype pollution flaw via startsWith() affects the Convict library (CVE-2026-33864). Review usage and inputs for `Convict`. #infosec #vulnerability #javascript https://www.pulsepatch.io/posts/cve-2026-33864-convict-prototype-pollution

    Post summary

    A critical prototype pollution vulnerability (CVE‑2026‑33864) in the Convict library is disclosed, identified as a startsWith() issue, but no proof‑of‑concept, exploit, or patch information is provided.

    0000031
    6 followersView on X

Explore more