← Vulnerability feed

Vulnerability record · CVE-2019-11358 · published 20 April 2019

CVE-2019-11358: jQuery extend() prototype pollution via unsanitized __proto__

Jquery · Jquery

jQuery before 3.4.0 mishandles jQuery.extend(true, {}, ...) so that an unsanitized source object containing an enumerable __proto__ property can extend the native Object.prototype. This prototype pollution affects jQuery itself and products embedding it, including Drupal, Backdrop CMS, and numerous enterprise applications. Because the vulnerable library is widely bundled, the flaw has a very large installed base even though the direct impact per instance is limited.

6.1 CVSS 3.1 Medium EPSS 87% · top 0.3% CWE-1321 · Prototype pollution
6.1CVSS 3.1 base score, v2 4.3
87%EPSS exploitation probability, 30 days
NoNot in CISA KEV
105Affected product versions listed by NVD
146References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityThe direct CVSS impact is medium and requires user interaction, but the extremely high EPSS score and the very broad set of affected products make this a high-priority dependency to remediate.

What it is

jQuery before 3.4.0 mishandles jQuery.extend(true, {}, ...) so that an unsanitized source object containing an enumerable __proto__ property can extend the native Object.prototype. This prototype pollution affects jQuery itself and products embedding it, including Drupal, Backdrop CMS, and numerous enterprise applications. Because the vulnerable library is widely bundled, the flaw has a very large installed base even though the direct impact per instance is limited.

Impact

An attacker can pollute Object.prototype, altering application behavior and potentially enabling client-side script execution or logic bypass in affected pages. The CVSS vector rates confidentiality and integrity impact as low, so the direct gain is limited but can be chained with other flaws.

Attack surface

Reached over the network through a crafted object passed to jQuery.extend(true, {}, ...), typically via a web page or application input. The CVSS vector requires user interaction (UI:R) and no privileges (PR:N), so a victim must load or interact with attacker-influenced content.

Exploitation

Not listed in CISA KEV and no ransomware groups are documented using it, but EPSS is very high (0.87218, 99.7th percentile), indicating strong predicted exploitation activity; references include patch and vendor advisory tags.

What to do

  • Upgrade jQuery to 3.4.0 or later, or apply the vendor patch commit 753d591aea698e57d6db58c9f722cd0808619b1b.
  • Update or patch downstream products that bundle jQuery (Drupal, Backdrop CMS, and other listed vendors) per their security advisories.
  • Avoid passing untrusted objects into jQuery.extend(true, {}, ...) and sanitize or reject keys such as __proto__ and constructor.prototype.
  • Use a software composition analysis or RetireJS-style scan to find bundled jQuery versions below 3.4.0 across web applications.
  • Where immediate upgrade is not possible, apply vendor backports or compensating input validation at the application layer.

Detection

  • Scan web assets and JavaScript bundles for jQuery versions below 3.4.0.
  • Monitor application logs and client-side telemetry for requests or payloads containing __proto__ or constructor.prototype keys.
  • Review dependency manifests and SBOMs for the affected products and vendors listed in the record.
  • Track vendor advisories and errata for the listed products to confirm patched versions are deployed.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

105 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00006.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00025.html Mailing ListThird Party Advisory
http://packetstormsecurity.com/files/152787/dotCMS-5.1.1-Vulnerable-Dependencies.html Third Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/153237/RetireJS-CORS-Issue-Script-Execution.html Third Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/156743/OctoberCMS-Insecure-Dependencies.html Third Party AdvisoryVDB Entry
http://seclists.org/fulldisclosure/2019/May/10 Mailing ListThird Party Advisory
http://seclists.org/fulldisclosure/2019/May/11 Mailing ListPatchThird Party Advisory
http://seclists.org/fulldisclosure/2019/May/13 Mailing ListPatchThird Party Advisory
http://www.openwall.com/lists/oss-security/2019/06/03/2 Mailing ListPatchThird Party Advisory
http://www.securityfocus.com/bid/108023 Broken LinkThird Party AdvisoryVDB Entry
https://access.redhat.com/errata/RHBA-2019:1570 Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:1456 Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:2587 Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:3023 Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:3024 Third Party Advisory
https://backdropcms.org/security/backdrop-sa-core-2019-009 Third Party Advisory
https://blog.jquery.com/2019/04/10/jquery-3-4-0-released/ Release NotesVendor Advisory
https://github.com/jquery/jquery/commit/753d591aea698e57d6db58c9f722cd0808619b1b PatchThird Party Advisory
https://github.com/jquery/jquery/pull/4333 PatchThird Party Advisory
https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44601 Third Party Advisory
https://lists.apache.org/thread.html/08720ef215ee7ab3386c05a1a90a7d1c852bf0706f176a7816bf65fc%40%3Ccommits.airflow.apach Issue Tracking
https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org% Issue Tracking
https://lists.apache.org/thread.html/5928aa293e39d248266472210c50f176cac1535220f2486e6a7fa844%40%3Ccommits.airflow.apach Issue Tracking
https://lists.apache.org/thread.html/6097cdbd6f0a337bedd9bb5cc441b2d525ff002a96531de367e4259f%40%3Ccommits.airflow.apach Issue Tracking
https://lists.apache.org/thread.html/88fb0362fd40e5b605ea8149f63241537b8b6fb5bfa315391fc5cbb7%40%3Ccommits.airflow.apach Issue Tracking
https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org% Issue Tracking
https://lists.apache.org/thread.html/b736d0784cf02f5a30fbb4c5902762a15ad6d47e17e2c5a17b7d6205%40%3Ccommits.airflow.apach Issue Tracking
https://lists.apache.org/thread.html/ba79cf1658741e9f146e4c59b50aee56656ea95d841d358d006c18b6%40%3Ccommits.roller.apache Issue Tracking
https://lists.apache.org/thread.html/bcce5a9c532b386c68dab2f6b3ce8b0cc9b950ec551766e76391caa3%40%3Ccommits.nifi.apache.o Issue Tracking
https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.o Issue Tracking
https://lists.apache.org/thread.html/r2041a75d3fc09dec55adfd95d598b38d22715303f65c997c054844c9%40%3Cissues.flink.apache. Issue Tracking
https://lists.apache.org/thread.html/r2baacab6e0acb5a2092eb46ae04fd6c3e8277b4fd79b1ffb7f3254fa%40%3Cissues.flink.apache. Issue Tracking
https://lists.apache.org/thread.html/r38f0d1aa3c923c22977fe7376508f030f22e22c1379fbb155bf29766%40%3Cdev.syncope.apache.o Issue Tracking
https://lists.apache.org/thread.html/r41b5bfe009c845f67d4f68948cc9419ac2d62e287804aafd72892b08%40%3Cissues.flink.apache. Issue Tracking
https://lists.apache.org/thread.html/r7aac081cbddb6baa24b75e74abf0929bf309b176755a53e3ed810355%40%3Cdev.flink.apache.org Issue Tracking
https://lists.apache.org/thread.html/r7d64895cc4dff84d0becfc572b20c0e4bf9bfa7b10c6f5f73e783734%40%3Cdev.storm.apache.org Issue Tracking
https://lists.apache.org/thread.html/r7e8ebccb7c022e41295f6fdb7b971209b83702339f872ddd8cf8bf73%40%3Cissues.flink.apache. Issue Tracking
https://lists.apache.org/thread.html/rac25da84ecdcd36f6de5ad0d255f4e967209bbbebddb285e231da37d%40%3Cissues.flink.apache. Issue Tracking
https://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b%40%3Ccommits.nifi.apache. Issue Tracking
https://lists.debian.org/debian-lts-announce/2019/05/msg00006.html Mailing ListThird Party Advisory

Track CVE-2019-11358 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2025-32433Erlang/OTP SSH server missing authentication allows remote code executionErlang/OTP SSH servers before OTP-27.3.3, OTP-26.2.5.11 and OTP-25.3.2.20 mishandle SSH protocol messages, letting an unauthenticated attacker execut…KEVEPSS 99%analysed10.0CVE-2025-24201Apple WebKit out-of-bounds write allows sandbox escapeCVE-2025-24201 is an out-of-bounds write in Apple's WebKit that was addressed with improved checks. Maliciously crafted web content may break out of …KEVEPSS 3.8%analysed10.0CVE-2021-44228Apache Log4j2 JNDI lookup remote code executionApache Log4j2 versions 2.0-beta9 through 2.15.0 (excluding 2.12.2, 2.12.3, and 2.3.1) do not protect against attacker-controlled LDAP and other JNDI …KEVEPSS 100%analysed9.8CVE-2026-9082Drupal core SQL injection in unauthenticated request pathDrupal core contains a SQL injection flaw (CWE-89) caused by improper neutralization of special elements in SQL commands. It affects multiple core br…KEVEPSS 16%analysed9.8CVE-2026-24061GNU Inetutils telnetd argument injection allows remote auth bypasstelnetd in GNU Inetutils through 2.7 fails to sanitize the USER environment variable, so a value such as "-f root" is passed as an argument to login …KEVEPSS 99%analysed9.8CVE-2025-39682Linux kernel TLS zero-length record handling flaw on rx_listThe Linux kernel TLS receive path mishandles zero-length records that arrive from the rx_list, breaking the assumption that a record type change cann…KEVEPSS 2.9%analysed9.8CVE-2025-24813Apache Tomcat Default Servlet path equivalence enables RCE and file disclosureApache Tomcat mishandles path equivalence for names containing an internal dot, letting a remote unauthenticated attacker write files through the Def…KEVEPSS 100%analysed9.8CVE-2024-9680Mozilla Firefox and Thunderbird use-after-free in Animation timelinesA use-after-free flaw in Animation timelines allows an attacker to execute code in the content process of Firefox and Thunderbird. Mozilla reports ex…KEVEPSS 23%analysed

Source: NIST National Vulnerability Database (record CVE-2019-11358), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.