CVE detail
CVE-2019-19507 — CVE-2019-19507
Published 2019-12-02 · Modified 2026-06-17 · Vendor json_pattern_validator_project · Product json_pattern_validator · Source nvd
MEDIUM
severity
CVSS-derived band
0.0097
EPSS probability
exploitation probability, 30d
59.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
In jpv (aka Json Pattern Validator) before 2.1.1, compareCommon() can be bypassed because certain internal attributes can be overwritten via a conflicting name, as demonstrated by 'constructor': {'name':'Array'}. This affects validate(). Hence, a crafted payload can overwrite this builtin attribute to manipulate the type detection result.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References