Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-21907

44
FAUCET Score

CVE-2024-21907 is a denial-of-service vulnerability affecting Newtonsoft.Json versions prior to 13.0.1. Specially crafted data passed to the JsonConvert.DeserializeObject method can trigger a StackOverflow exception, leading to a denial of service. This vulnerability has a CVSS score of 7.5 (High), indicating it can be exploited remotely and unauthenticated, with a high impact on availability. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), it has garnered some community discussion and media coverage, suggesting awareness of the flaw.

Impacted Technologies

VendorProductVersion(s)CPE
< 13.0.1CPE matchmatch criteria
cpe:2.3:a:newtonsoft:json.net:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
32.91%
Probability of exploitation in next 30 days
EPSS Percentile
98.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.3291 is in the 97th percentile among its peer group of 51,506 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (8)

github_advisorypatch availablevia nvd_reference
View patch
microsoftpatch availablevia msrc
Product: Microsoft SQL Server 2017 for x64-based Systems (GDR)Fixed in: 14.0.2085.1
View patch
microsoftpatch availablevia msrc
Product: Microsoft SQL Server 2019 for x64-based Systems (GDR)Fixed in: 15.0.2145.1
View patch
microsoftpatch availablevia msrc
Product: Microsoft SQL Server 2016 for x64-based Systems Service Pack 3 (GDR)Fixed in: 13.0.6470.1
View patch
microsoftpatch availablevia msrc
Product: Microsoft SQL Server 2016 for x64-based Systems Service Pack 3 Azure Connect Feature PackFixed in: 13.0.7065.1
View patch
microsoftpatch availablevia msrc
Product: Microsoft SQL Server 2017 for x64-based Systems (CU 31)Fixed in: 14.0.3505.1
View patch
microsoftpatch availablevia msrc
Product: Microsoft SQL Server 2019 for x64-based Systems (CU 32)Fixed in: 15.0.4445.1
View patch
nugetpatch availablevia ghsa
Product: Newtonsoft.JsonFixed in: 13.0.1

Vendor Advisories (2)

microsoft2025-Sep/CVE-2024-21907

VulnCheck: CVE-2024-21907 Improper Handling of Exceptional Conditions in Newtonsoft.Json

Sep 9, 2025
nugetGHSA-5crp-9r3c-p9vrhigh

Improper Handling of Exceptional Conditions in Newtonsoft.Json

Jun 22, 2022

References

alephsecurity.com / 2018/10/22/StackOverflowException
Exploit
alephsecurity.com / vulns/aleph-2018004
Exploit
github.com / advisories/GHSA-5crp-9r3c-p9vr
Third Party Advisory
github.com / JamesNK/Newtonsoft.Json/commit/7e77bbe1beccceac4fc7b174b53abfefac278b66
Patch
github.com / JamesNK/Newtonsoft.Json/issues/2457
ExploitIssue TrackingThird Party Advisory
github.com / JamesNK/Newtonsoft.Json/pull/2462
Patch
security.snyk.io / vuln/SNYK-DOTNET-NEWTONSOFTJSON-2774678
ExploitThird Party Advisory
vulncheck.com / advisories/vc-advisory-GHSA-5crp-9r3c-p9vr
Third Party Advisory