{"id":"CVE-2016-10707","aliases":["GHSA-mhpp-875w-9cpv"],"url":"https://o3.security/vulnerability/CVE-2016-10707","summary":"Denial of Service in jquery","details":"jQuery 3.0.0-rc.1 is vulnerable to Denial of Service (DoS) due to removing a logic that lowercased attribute names. Any attribute getter using a mixed-cased name for boolean attributes goes into an infinite recursion, exceeding the stack call limit.","published":"2018-01-18T23:29:00.400Z","modified":"2026-07-08T12:43:14.799828Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Maven","name":"org.webjars.npm:jquery","fixedVersion":"3.0.0"},{"ecosystem":"npm","name":"jquery","fixedVersion":"3.0.0"},{"ecosystem":"NuGet","name":"jQuery","fixedVersion":"3.0.0"},{"ecosystem":"RubyGems","name":"jquery-rails","fixedVersion":"3.0.0"}],"fix":{"url":"https://github.com/jquery/jquery/pull/3134","label":"jquery/jquery#3134"},"references":[{"type":"ADVISORY","url":"https://snyk.io/vuln/npm:jquery:20160529"},{"type":"FIX","url":"https://github.com/jquery/jquery/issues/3133"},{"type":"FIX","url":"https://github.com/jquery/jquery/pull/3134"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T12:43:14.799828Z"}}