Back to search
CVE-2024-21907
Published: Jan 3, 2024
Modified: Nov 28, 2025
PUBLISHED
Description
Newtonsoft.Json before version 13.0.1 is affected by a mishandling of exceptional conditions vulnerability. Crafted data that is passed to the JsonConvert.DeserializeObject method may trigger a StackOverflow exception resulting in denial of service. Depending on the usage of the library, an unauthenticated and remote attacker may be able to cause the denial of service condition.
| Vendor | Product | Versions |
|---|---|---|
Unknown | Newtonsoft.Json | affected 0 - < 13.0.1 |
Weaknesses (CWE)
References
https://github.com/JamesNK/Newtonsoft.Json/issues/2457
issue-tracking
https://github.com/advisories/GHSA-5crp-9r3c-p9vr
third-party-advisory
https://vulncheck.com/advisories/vc-advisory-GHSA-5crp-9r3c-p9vr
third-party-advisory
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now