High severity7.5OSV Advisory· Published Jan 3, 2024· Updated Jul 14, 2026
CVE-2024-21907
CVE-2024-21907
Description
Newtonsoft.Json before version 13.0.1 is affected by a mishandling of exceptional conditions vulnerability. Crafted data that is passed to the JsonConvert.DeserializeObject method may trigger a StackOverflow exception resulting in denial of service. Depending on the usage of the library, an unauthenticated and remote attacker may be able to cause the denial of service condition.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
Newtonsoft.JsonNuGet | < 13.0.1 | 13.0.1 |
Affected products
3- Range: 1.3.1, 10.0.1, 10.0.2, …
Patches
Vulnerability mechanics
References
9- github.com/JamesNK/Newtonsoft.Json/commit/7e77bbe1beccceac4fc7b174b53abfefac278b66nvdPatchWEB
- github.com/JamesNK/Newtonsoft.Json/pull/2462nvdPatchWEB
- alephsecurity.com/2018/10/22/StackOverflowException/nvdExploit
- alephsecurity.com/vulns/aleph-2018004nvdExploitWEB
- github.com/JamesNK/Newtonsoft.Json/issues/2457nvdExploitIssue TrackingThird Party AdvisoryWEB
- security.snyk.io/vuln/SNYK-DOTNET-NEWTONSOFTJSON-2774678nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-5crp-9r3c-p9vrnvdThird Party AdvisoryADVISORY
- vulncheck.com/advisories/vc-advisory-GHSA-5crp-9r3c-p9vrnvdThird Party Advisory
- alephsecurity.com/2018/10/22/StackOverflowExceptionghsaWEB
News mentions
0No linked articles in our index yet.