Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-57699

22
FAUCET Score

CVE-2024-57699 is a high-severity Denial of Service (DoS) vulnerability affecting Netplex Json-smart versions 2.5.0 through 2.5.1. An attacker can trigger a stack exhaustion by providing specially crafted JSON input containing numerous '{' characters, leading to service disruption. This issue is an incomplete fix for a previous vulnerability, CVE-2023-1370. The vulnerability has a CVSS score of 7.5, indicating a network-based attack with low complexity and high impact on availability, requiring no user interaction or privileges. While there is no evidence of active exploitation, public exploit code, or KEV listing, the vulnerability has garnered some community discussion and media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
N/AN/A
n/aCNA affected

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.57%
Probability of exploitation in next 30 days
EPSS Percentile
43.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0057 is in the 21st percentile among its peer group of 51,553 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (25)

mavenpatch availablevia ghsa
Product: net.minidev:json-smartFixed in: 2.5.2
redhatpatch availablevia redhat_api
Product: HawtIO HawtIO 4.2.0Fixed in: json-smart
View patch
redhatpatch availablevia redhat_api
Product: OCP-Tools-4.12-RHEL-8Fixed in: jenkins-0:2.504.2.1750932984-3.el8
View patch
redhatpatch availablevia redhat_api
Product: OCP-Tools-4.12-RHEL-8Fixed in: jenkins-2-plugins-0:4.12.1750933270-1.el8
View patch
redhatpatch availablevia redhat_api
Product: OCP-Tools-4.13-RHEL-8Fixed in: jenkins-0:2.504.2.1750916374-3.el8
View patch
redhatpatch availablevia redhat_api
Product: OCP-Tools-4.13-RHEL-8Fixed in: jenkins-2-plugins-0:4.13.1750916671-1.el8
View patch
redhatpatch availablevia redhat_api
Product: OCP-Tools-4.14-RHEL-8Fixed in: jenkins-0:2.504.2.1750903189-3.el8
View patch
redhatpatch availablevia redhat_api
Product: OCP-Tools-4.14-RHEL-8Fixed in: jenkins-2-plugins-0:4.14.1750903529-1.el8
View patch
redhatpatch availablevia redhat_api
Product: OCP-Tools-4.15-RHEL-8Fixed in: jenkins-0:2.504.2.1750856366-3.el8
View patch
redhatpatch availablevia redhat_api
Product: OCP-Tools-4.15-RHEL-8Fixed in: jenkins-2-plugins-0:4.15.1750856638-1.el8
View patch
redhatpatch availablevia redhat_api
Product: OCP-Tools-4.16-RHEL-9Fixed in: jenkins-0:2.504.2.1750857144-3.el9
View patch
redhatpatch availablevia redhat_api
Product: OCP-Tools-4.16-RHEL-9Fixed in: jenkins-2-plugins-0:4.16.1750857315-1.el9
View patch
redhatpatch availablevia redhat_api
Product: OCP-Tools-4.17-RHEL-9Fixed in: jenkins-2-plugins-0:4.17.1750851950-1.el9
View patch
redhatpatch availablevia redhat_api
Product: OCP-Tools-4.18-RHEL-9Fixed in: jenkins-0:2.504.2.1750846524-3.el9
View patch
redhatpatch availablevia redhat_api
Product: OCP-Tools-4.18-RHEL-9Fixed in: jenkins-2-plugins-0:4.18.1750846854-1.el9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat build of Apache Camel 4.8.5 for Spring BootFixed in: json-smart
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Build of Apache Camel 4.8 for Quarkus 3.15Fixed in: quarkus-camel-bom
View patch
redhatpatch availablevia redhat_api
Product: OCP-Tools-4.17-RHEL-9Fixed in: jenkins-0:2.504.2.1750851690-3.el9
View patch
redhatno patchvia redhat_api
Product: streams for Apache KafkaFixed in: net.minidev-json-smart
redhatno patchvia redhat_api
Product: streams for Apache Kafka 2Fixed in: json-smart
redhatno patchvia redhat_api
Product: Red Hat build of Debezium 2Fixed in: json-smart
redhatno patchvia redhat_api
Product: Red Hat build of Apicurio Registry 2Fixed in: json-smart
redhatno patchvia redhat_api
Product: streams for Apache KafkaFixed in: json-smart-action
redhatend of lifevia redhat_api
Product: streams for Apache KafkaFixed in: json-smart
redhatend of lifevia redhat_api
Product: Red Hat Data Grid 8Fixed in: json-smart

Vendor Advisories (2)

mavenGHSA-pq2g-wx69-c263high

Netplex Json-smart Uncontrolled Recursion vulnerability

Feb 6, 2025
redhatCVE-2024-57699Important

json-smart: Potential DoS via stack exhaustion (incomplete fix for CVE-2023-1370)

Feb 5, 2025

References

github.com / TurtleLiu/Vul_PoC/tree/main/CVE-2024-57699
nvd.nist.gov / vuln/detail/cve-2023-1370