Newtonsoft.Json
Json.NET is a popular high-performance JSON framework for .NET
Activity
- Latest release
- 8mo ago
- Total releases
- 54
- Cadence
- ~43 days
- Last 12 months
- 1
Details
- License
- MIT
- First release
- Jan 08, 2011
| Version | Released | |
|---|---|---|
13.0.5-beta1
pre
|
13.0.5-beta1
pre
Dependencies (6)
|
|
13.0.4
patch
|
13.0.4
patch
Dependencies (6)
|
|
13.0.3
patch
|
13.0.3
patch
Dependencies (6)
|
|
13.0.2
patch
|
13.0.2
patch
Dependencies (6)
|
|
13.0.1
major
|
13.0.1
major
Dependencies (6)
|
|
12.0.3
patch
1 CVE
CVE-2024-21907
GHSA-5crp-9r3c-p9vr
Jun 22, 2022
Improper Handling of Exceptional Conditions in Newtonsoft.Json
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Newtonsoft.Json prior to version 13.0.1 is vulnerable to Insecure Defaults due to improper handling of expressions with high nesting level that lead to StackOverFlow exception or high CPU and RAM usage. Exploiting this vulnerability results in Denial Of Service (DoS). The serialization and deserialization path have different properties regarding the issue. Deserializing methods (like Serializing methods (like To mitigate the issue one either need to update Newtonsoft.Json to 13.0.1 or set
Repro code:
Additional affected product and version informationThe original statement about the problem only affecting IIS applications is misleading. Any application is affected, however the IIS has a behavior that stops restarting the instance after some time resulting in a harder-to-fix DoS.** Affected versions
10.0.1
10.0.1-beta1
10.0.2
10.0.3
11.0.1
11.0.1-beta1
11.0.1-beta2
11.0.1-beta3
11.0.2
12.0.1
12.0.1-beta1
12.0.1-beta2
+ 62 more Show less
12.0.2
12.0.2-beta1
12.0.2-beta2
12.0.2-beta3
12.0.3
12.0.3-beta1
12.0.3-beta2
13.0.1-beta1
13.0.1-beta2
3.5.8
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.5.1
4.5.10
4.5.11
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
6.0.1
6.0.1-beta1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.1
7.0.1-beta1
7.0.1-beta2
7.0.1-beta3
8.0.1
8.0.1-beta1
8.0.1-beta2
8.0.1-beta3
8.0.1-beta4
8.0.2
8.0.3
8.0.4-beta1
9.0.1
9.0.1-beta1
9.0.2-beta1
9.0.2-beta2
Fixed in
13.0.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
12.0.3
patch
Dependencies (6)
|
|
12.0.2
patch
1 CVE
CVE-2024-21907
GHSA-5crp-9r3c-p9vr
Jun 22, 2022
Improper Handling of Exceptional Conditions in Newtonsoft.Json
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Newtonsoft.Json prior to version 13.0.1 is vulnerable to Insecure Defaults due to improper handling of expressions with high nesting level that lead to StackOverFlow exception or high CPU and RAM usage. Exploiting this vulnerability results in Denial Of Service (DoS). The serialization and deserialization path have different properties regarding the issue. Deserializing methods (like Serializing methods (like To mitigate the issue one either need to update Newtonsoft.Json to 13.0.1 or set
Repro code:
Additional affected product and version informationThe original statement about the problem only affecting IIS applications is misleading. Any application is affected, however the IIS has a behavior that stops restarting the instance after some time resulting in a harder-to-fix DoS.** Affected versions
10.0.1
10.0.1-beta1
10.0.2
10.0.3
11.0.1
11.0.1-beta1
11.0.1-beta2
11.0.1-beta3
11.0.2
12.0.1
12.0.1-beta1
12.0.1-beta2
+ 62 more Show less
12.0.2
12.0.2-beta1
12.0.2-beta2
12.0.2-beta3
12.0.3
12.0.3-beta1
12.0.3-beta2
13.0.1-beta1
13.0.1-beta2
3.5.8
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.5.1
4.5.10
4.5.11
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
6.0.1
6.0.1-beta1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.1
7.0.1-beta1
7.0.1-beta2
7.0.1-beta3
8.0.1
8.0.1-beta1
8.0.1-beta2
8.0.1-beta3
8.0.1-beta4
8.0.2
8.0.3
8.0.4-beta1
9.0.1
9.0.1-beta1
9.0.2-beta1
9.0.2-beta2
Fixed in
13.0.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
12.0.2
patch
Dependencies (6)
|
|
12.0.1
major
1 CVE
CVE-2024-21907
GHSA-5crp-9r3c-p9vr
Jun 22, 2022
Improper Handling of Exceptional Conditions in Newtonsoft.Json
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Newtonsoft.Json prior to version 13.0.1 is vulnerable to Insecure Defaults due to improper handling of expressions with high nesting level that lead to StackOverFlow exception or high CPU and RAM usage. Exploiting this vulnerability results in Denial Of Service (DoS). The serialization and deserialization path have different properties regarding the issue. Deserializing methods (like Serializing methods (like To mitigate the issue one either need to update Newtonsoft.Json to 13.0.1 or set
Repro code:
Additional affected product and version informationThe original statement about the problem only affecting IIS applications is misleading. Any application is affected, however the IIS has a behavior that stops restarting the instance after some time resulting in a harder-to-fix DoS.** Affected versions
10.0.1
10.0.1-beta1
10.0.2
10.0.3
11.0.1
11.0.1-beta1
11.0.1-beta2
11.0.1-beta3
11.0.2
12.0.1
12.0.1-beta1
12.0.1-beta2
+ 62 more Show less
12.0.2
12.0.2-beta1
12.0.2-beta2
12.0.2-beta3
12.0.3
12.0.3-beta1
12.0.3-beta2
13.0.1-beta1
13.0.1-beta2
3.5.8
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.5.1
4.5.10
4.5.11
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
6.0.1
6.0.1-beta1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.1
7.0.1-beta1
7.0.1-beta2
7.0.1-beta3
8.0.1
8.0.1-beta1
8.0.1-beta2
8.0.1-beta3
8.0.1-beta4
8.0.2
8.0.3
8.0.4-beta1
9.0.1
9.0.1-beta1
9.0.2-beta1
9.0.2-beta2
Fixed in
13.0.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
12.0.1
major
Dependencies (6)
|
|
11.0.2
patch
1 CVE
CVE-2024-21907
GHSA-5crp-9r3c-p9vr
Jun 22, 2022
Improper Handling of Exceptional Conditions in Newtonsoft.Json
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Newtonsoft.Json prior to version 13.0.1 is vulnerable to Insecure Defaults due to improper handling of expressions with high nesting level that lead to StackOverFlow exception or high CPU and RAM usage. Exploiting this vulnerability results in Denial Of Service (DoS). The serialization and deserialization path have different properties regarding the issue. Deserializing methods (like Serializing methods (like To mitigate the issue one either need to update Newtonsoft.Json to 13.0.1 or set
Repro code:
Additional affected product and version informationThe original statement about the problem only affecting IIS applications is misleading. Any application is affected, however the IIS has a behavior that stops restarting the instance after some time resulting in a harder-to-fix DoS.** Affected versions
10.0.1
10.0.1-beta1
10.0.2
10.0.3
11.0.1
11.0.1-beta1
11.0.1-beta2
11.0.1-beta3
11.0.2
12.0.1
12.0.1-beta1
12.0.1-beta2
+ 62 more Show less
12.0.2
12.0.2-beta1
12.0.2-beta2
12.0.2-beta3
12.0.3
12.0.3-beta1
12.0.3-beta2
13.0.1-beta1
13.0.1-beta2
3.5.8
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.5.1
4.5.10
4.5.11
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
6.0.1
6.0.1-beta1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.1
7.0.1-beta1
7.0.1-beta2
7.0.1-beta3
8.0.1
8.0.1-beta1
8.0.1-beta2
8.0.1-beta3
8.0.1-beta4
8.0.2
8.0.3
8.0.4-beta1
9.0.1
9.0.1-beta1
9.0.2-beta1
9.0.2-beta2
Fixed in
13.0.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
11.0.2
patch
Dependencies (6)
|
|
11.0.1
major
1 CVE
CVE-2024-21907
GHSA-5crp-9r3c-p9vr
Jun 22, 2022
Improper Handling of Exceptional Conditions in Newtonsoft.Json
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Newtonsoft.Json prior to version 13.0.1 is vulnerable to Insecure Defaults due to improper handling of expressions with high nesting level that lead to StackOverFlow exception or high CPU and RAM usage. Exploiting this vulnerability results in Denial Of Service (DoS). The serialization and deserialization path have different properties regarding the issue. Deserializing methods (like Serializing methods (like To mitigate the issue one either need to update Newtonsoft.Json to 13.0.1 or set
Repro code:
Additional affected product and version informationThe original statement about the problem only affecting IIS applications is misleading. Any application is affected, however the IIS has a behavior that stops restarting the instance after some time resulting in a harder-to-fix DoS.** Affected versions
10.0.1
10.0.1-beta1
10.0.2
10.0.3
11.0.1
11.0.1-beta1
11.0.1-beta2
11.0.1-beta3
11.0.2
12.0.1
12.0.1-beta1
12.0.1-beta2
+ 62 more Show less
12.0.2
12.0.2-beta1
12.0.2-beta2
12.0.2-beta3
12.0.3
12.0.3-beta1
12.0.3-beta2
13.0.1-beta1
13.0.1-beta2
3.5.8
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.5.1
4.5.10
4.5.11
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
6.0.1
6.0.1-beta1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.1
7.0.1-beta1
7.0.1-beta2
7.0.1-beta3
8.0.1
8.0.1-beta1
8.0.1-beta2
8.0.1-beta3
8.0.1-beta4
8.0.2
8.0.3
8.0.4-beta1
9.0.1
9.0.1-beta1
9.0.2-beta1
9.0.2-beta2
Fixed in
13.0.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
11.0.1
major
Dependencies (6)
|
|
10.0.3
patch
1 CVE
CVE-2024-21907
GHSA-5crp-9r3c-p9vr
Jun 22, 2022
Improper Handling of Exceptional Conditions in Newtonsoft.Json
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Newtonsoft.Json prior to version 13.0.1 is vulnerable to Insecure Defaults due to improper handling of expressions with high nesting level that lead to StackOverFlow exception or high CPU and RAM usage. Exploiting this vulnerability results in Denial Of Service (DoS). The serialization and deserialization path have different properties regarding the issue. Deserializing methods (like Serializing methods (like To mitigate the issue one either need to update Newtonsoft.Json to 13.0.1 or set
Repro code:
Additional affected product and version informationThe original statement about the problem only affecting IIS applications is misleading. Any application is affected, however the IIS has a behavior that stops restarting the instance after some time resulting in a harder-to-fix DoS.** Affected versions
10.0.1
10.0.1-beta1
10.0.2
10.0.3
11.0.1
11.0.1-beta1
11.0.1-beta2
11.0.1-beta3
11.0.2
12.0.1
12.0.1-beta1
12.0.1-beta2
+ 62 more Show less
12.0.2
12.0.2-beta1
12.0.2-beta2
12.0.2-beta3
12.0.3
12.0.3-beta1
12.0.3-beta2
13.0.1-beta1
13.0.1-beta2
3.5.8
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.5.1
4.5.10
4.5.11
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
6.0.1
6.0.1-beta1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.1
7.0.1-beta1
7.0.1-beta2
7.0.1-beta3
8.0.1
8.0.1-beta1
8.0.1-beta2
8.0.1-beta3
8.0.1-beta4
8.0.2
8.0.3
8.0.4-beta1
9.0.1
9.0.1-beta1
9.0.2-beta1
9.0.2-beta2
Fixed in
13.0.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
10.0.3
patch
Dependencies (6)
|
|
10.0.2
patch
1 CVE
CVE-2024-21907
GHSA-5crp-9r3c-p9vr
Jun 22, 2022
Improper Handling of Exceptional Conditions in Newtonsoft.Json
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Newtonsoft.Json prior to version 13.0.1 is vulnerable to Insecure Defaults due to improper handling of expressions with high nesting level that lead to StackOverFlow exception or high CPU and RAM usage. Exploiting this vulnerability results in Denial Of Service (DoS). The serialization and deserialization path have different properties regarding the issue. Deserializing methods (like Serializing methods (like To mitigate the issue one either need to update Newtonsoft.Json to 13.0.1 or set
Repro code:
Additional affected product and version informationThe original statement about the problem only affecting IIS applications is misleading. Any application is affected, however the IIS has a behavior that stops restarting the instance after some time resulting in a harder-to-fix DoS.** Affected versions
10.0.1
10.0.1-beta1
10.0.2
10.0.3
11.0.1
11.0.1-beta1
11.0.1-beta2
11.0.1-beta3
11.0.2
12.0.1
12.0.1-beta1
12.0.1-beta2
+ 62 more Show less
12.0.2
12.0.2-beta1
12.0.2-beta2
12.0.2-beta3
12.0.3
12.0.3-beta1
12.0.3-beta2
13.0.1-beta1
13.0.1-beta2
3.5.8
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.5.1
4.5.10
4.5.11
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
6.0.1
6.0.1-beta1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.1
7.0.1-beta1
7.0.1-beta2
7.0.1-beta3
8.0.1
8.0.1-beta1
8.0.1-beta2
8.0.1-beta3
8.0.1-beta4
8.0.2
8.0.3
8.0.4-beta1
9.0.1
9.0.1-beta1
9.0.2-beta1
9.0.2-beta2
Fixed in
13.0.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
10.0.2
patch
Dependencies (6)
|
|
10.0.1
major
1 CVE
CVE-2024-21907
GHSA-5crp-9r3c-p9vr
Jun 22, 2022
Improper Handling of Exceptional Conditions in Newtonsoft.Json
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Newtonsoft.Json prior to version 13.0.1 is vulnerable to Insecure Defaults due to improper handling of expressions with high nesting level that lead to StackOverFlow exception or high CPU and RAM usage. Exploiting this vulnerability results in Denial Of Service (DoS). The serialization and deserialization path have different properties regarding the issue. Deserializing methods (like Serializing methods (like To mitigate the issue one either need to update Newtonsoft.Json to 13.0.1 or set
Repro code:
Additional affected product and version informationThe original statement about the problem only affecting IIS applications is misleading. Any application is affected, however the IIS has a behavior that stops restarting the instance after some time resulting in a harder-to-fix DoS.** Affected versions
10.0.1
10.0.1-beta1
10.0.2
10.0.3
11.0.1
11.0.1-beta1
11.0.1-beta2
11.0.1-beta3
11.0.2
12.0.1
12.0.1-beta1
12.0.1-beta2
+ 62 more Show less
12.0.2
12.0.2-beta1
12.0.2-beta2
12.0.2-beta3
12.0.3
12.0.3-beta1
12.0.3-beta2
13.0.1-beta1
13.0.1-beta2
3.5.8
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.5.1
4.5.10
4.5.11
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
6.0.1
6.0.1-beta1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.1
7.0.1-beta1
7.0.1-beta2
7.0.1-beta3
8.0.1
8.0.1-beta1
8.0.1-beta2
8.0.1-beta3
8.0.1-beta4
8.0.2
8.0.3
8.0.4-beta1
9.0.1
9.0.1-beta1
9.0.2-beta1
9.0.2-beta2
Fixed in
13.0.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
10.0.1
major
Dependencies (26)
+ 18 more |
|
9.0.1
major
1 CVE
CVE-2024-21907
GHSA-5crp-9r3c-p9vr
Jun 22, 2022
Improper Handling of Exceptional Conditions in Newtonsoft.Json
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Newtonsoft.Json prior to version 13.0.1 is vulnerable to Insecure Defaults due to improper handling of expressions with high nesting level that lead to StackOverFlow exception or high CPU and RAM usage. Exploiting this vulnerability results in Denial Of Service (DoS). The serialization and deserialization path have different properties regarding the issue. Deserializing methods (like Serializing methods (like To mitigate the issue one either need to update Newtonsoft.Json to 13.0.1 or set
Repro code:
Additional affected product and version informationThe original statement about the problem only affecting IIS applications is misleading. Any application is affected, however the IIS has a behavior that stops restarting the instance after some time resulting in a harder-to-fix DoS.** Affected versions
10.0.1
10.0.1-beta1
10.0.2
10.0.3
11.0.1
11.0.1-beta1
11.0.1-beta2
11.0.1-beta3
11.0.2
12.0.1
12.0.1-beta1
12.0.1-beta2
+ 62 more Show less
12.0.2
12.0.2-beta1
12.0.2-beta2
12.0.2-beta3
12.0.3
12.0.3-beta1
12.0.3-beta2
13.0.1-beta1
13.0.1-beta2
3.5.8
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.5.1
4.5.10
4.5.11
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
6.0.1
6.0.1-beta1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.1
7.0.1-beta1
7.0.1-beta2
7.0.1-beta3
8.0.1
8.0.1-beta1
8.0.1-beta2
8.0.1-beta3
8.0.1-beta4
8.0.2
8.0.3
8.0.4-beta1
9.0.1
9.0.1-beta1
9.0.2-beta1
9.0.2-beta2
Fixed in
13.0.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
9.0.1
major
Dependencies (22)
+ 14 more |
|
8.0.3
patch
1 CVE
CVE-2024-21907
GHSA-5crp-9r3c-p9vr
Jun 22, 2022
Improper Handling of Exceptional Conditions in Newtonsoft.Json
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Newtonsoft.Json prior to version 13.0.1 is vulnerable to Insecure Defaults due to improper handling of expressions with high nesting level that lead to StackOverFlow exception or high CPU and RAM usage. Exploiting this vulnerability results in Denial Of Service (DoS). The serialization and deserialization path have different properties regarding the issue. Deserializing methods (like Serializing methods (like To mitigate the issue one either need to update Newtonsoft.Json to 13.0.1 or set
Repro code:
Additional affected product and version informationThe original statement about the problem only affecting IIS applications is misleading. Any application is affected, however the IIS has a behavior that stops restarting the instance after some time resulting in a harder-to-fix DoS.** Affected versions
10.0.1
10.0.1-beta1
10.0.2
10.0.3
11.0.1
11.0.1-beta1
11.0.1-beta2
11.0.1-beta3
11.0.2
12.0.1
12.0.1-beta1
12.0.1-beta2
+ 62 more Show less
12.0.2
12.0.2-beta1
12.0.2-beta2
12.0.2-beta3
12.0.3
12.0.3-beta1
12.0.3-beta2
13.0.1-beta1
13.0.1-beta2
3.5.8
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.5.1
4.5.10
4.5.11
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
6.0.1
6.0.1-beta1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.1
7.0.1-beta1
7.0.1-beta2
7.0.1-beta3
8.0.1
8.0.1-beta1
8.0.1-beta2
8.0.1-beta3
8.0.1-beta4
8.0.2
8.0.3
8.0.4-beta1
9.0.1
9.0.1-beta1
9.0.2-beta1
9.0.2-beta2
Fixed in
13.0.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
8.0.3
patch
|
|
8.0.2
patch
1 CVE
CVE-2024-21907
GHSA-5crp-9r3c-p9vr
Jun 22, 2022
Improper Handling of Exceptional Conditions in Newtonsoft.Json
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Newtonsoft.Json prior to version 13.0.1 is vulnerable to Insecure Defaults due to improper handling of expressions with high nesting level that lead to StackOverFlow exception or high CPU and RAM usage. Exploiting this vulnerability results in Denial Of Service (DoS). The serialization and deserialization path have different properties regarding the issue. Deserializing methods (like Serializing methods (like To mitigate the issue one either need to update Newtonsoft.Json to 13.0.1 or set
Repro code:
Additional affected product and version informationThe original statement about the problem only affecting IIS applications is misleading. Any application is affected, however the IIS has a behavior that stops restarting the instance after some time resulting in a harder-to-fix DoS.** Affected versions
10.0.1
10.0.1-beta1
10.0.2
10.0.3
11.0.1
11.0.1-beta1
11.0.1-beta2
11.0.1-beta3
11.0.2
12.0.1
12.0.1-beta1
12.0.1-beta2
+ 62 more Show less
12.0.2
12.0.2-beta1
12.0.2-beta2
12.0.2-beta3
12.0.3
12.0.3-beta1
12.0.3-beta2
13.0.1-beta1
13.0.1-beta2
3.5.8
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.5.1
4.5.10
4.5.11
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
6.0.1
6.0.1-beta1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.1
7.0.1-beta1
7.0.1-beta2
7.0.1-beta3
8.0.1
8.0.1-beta1
8.0.1-beta2
8.0.1-beta3
8.0.1-beta4
8.0.2
8.0.3
8.0.4-beta1
9.0.1
9.0.1-beta1
9.0.2-beta1
9.0.2-beta2
Fixed in
13.0.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
8.0.2
patch
|
|
8.0.1
major
1 CVE
CVE-2024-21907
GHSA-5crp-9r3c-p9vr
Jun 22, 2022
Improper Handling of Exceptional Conditions in Newtonsoft.Json
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Newtonsoft.Json prior to version 13.0.1 is vulnerable to Insecure Defaults due to improper handling of expressions with high nesting level that lead to StackOverFlow exception or high CPU and RAM usage. Exploiting this vulnerability results in Denial Of Service (DoS). The serialization and deserialization path have different properties regarding the issue. Deserializing methods (like Serializing methods (like To mitigate the issue one either need to update Newtonsoft.Json to 13.0.1 or set
Repro code:
Additional affected product and version informationThe original statement about the problem only affecting IIS applications is misleading. Any application is affected, however the IIS has a behavior that stops restarting the instance after some time resulting in a harder-to-fix DoS.** Affected versions
10.0.1
10.0.1-beta1
10.0.2
10.0.3
11.0.1
11.0.1-beta1
11.0.1-beta2
11.0.1-beta3
11.0.2
12.0.1
12.0.1-beta1
12.0.1-beta2
+ 62 more Show less
12.0.2
12.0.2-beta1
12.0.2-beta2
12.0.2-beta3
12.0.3
12.0.3-beta1
12.0.3-beta2
13.0.1-beta1
13.0.1-beta2
3.5.8
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.5.1
4.5.10
4.5.11
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
6.0.1
6.0.1-beta1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.1
7.0.1-beta1
7.0.1-beta2
7.0.1-beta3
8.0.1
8.0.1-beta1
8.0.1-beta2
8.0.1-beta3
8.0.1-beta4
8.0.2
8.0.3
8.0.4-beta1
9.0.1
9.0.1-beta1
9.0.2-beta1
9.0.2-beta2
Fixed in
13.0.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
8.0.1
major
|
|
7.0.1
major
1 CVE
CVE-2024-21907
GHSA-5crp-9r3c-p9vr
Jun 22, 2022
Improper Handling of Exceptional Conditions in Newtonsoft.Json
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Newtonsoft.Json prior to version 13.0.1 is vulnerable to Insecure Defaults due to improper handling of expressions with high nesting level that lead to StackOverFlow exception or high CPU and RAM usage. Exploiting this vulnerability results in Denial Of Service (DoS). The serialization and deserialization path have different properties regarding the issue. Deserializing methods (like Serializing methods (like To mitigate the issue one either need to update Newtonsoft.Json to 13.0.1 or set
Repro code:
Additional affected product and version informationThe original statement about the problem only affecting IIS applications is misleading. Any application is affected, however the IIS has a behavior that stops restarting the instance after some time resulting in a harder-to-fix DoS.** Affected versions
10.0.1
10.0.1-beta1
10.0.2
10.0.3
11.0.1
11.0.1-beta1
11.0.1-beta2
11.0.1-beta3
11.0.2
12.0.1
12.0.1-beta1
12.0.1-beta2
+ 62 more Show less
12.0.2
12.0.2-beta1
12.0.2-beta2
12.0.2-beta3
12.0.3
12.0.3-beta1
12.0.3-beta2
13.0.1-beta1
13.0.1-beta2
3.5.8
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.5.1
4.5.10
4.5.11
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
6.0.1
6.0.1-beta1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.1
7.0.1-beta1
7.0.1-beta2
7.0.1-beta3
8.0.1
8.0.1-beta1
8.0.1-beta2
8.0.1-beta3
8.0.1-beta4
8.0.2
8.0.3
8.0.4-beta1
9.0.1
9.0.1-beta1
9.0.2-beta1
9.0.2-beta2
Fixed in
13.0.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
7.0.1
major
|
|
6.0.8
patch
1 CVE
CVE-2024-21907
GHSA-5crp-9r3c-p9vr
Jun 22, 2022
Improper Handling of Exceptional Conditions in Newtonsoft.Json
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Newtonsoft.Json prior to version 13.0.1 is vulnerable to Insecure Defaults due to improper handling of expressions with high nesting level that lead to StackOverFlow exception or high CPU and RAM usage. Exploiting this vulnerability results in Denial Of Service (DoS). The serialization and deserialization path have different properties regarding the issue. Deserializing methods (like Serializing methods (like To mitigate the issue one either need to update Newtonsoft.Json to 13.0.1 or set
Repro code:
Additional affected product and version informationThe original statement about the problem only affecting IIS applications is misleading. Any application is affected, however the IIS has a behavior that stops restarting the instance after some time resulting in a harder-to-fix DoS.** Affected versions
10.0.1
10.0.1-beta1
10.0.2
10.0.3
11.0.1
11.0.1-beta1
11.0.1-beta2
11.0.1-beta3
11.0.2
12.0.1
12.0.1-beta1
12.0.1-beta2
+ 62 more Show less
12.0.2
12.0.2-beta1
12.0.2-beta2
12.0.2-beta3
12.0.3
12.0.3-beta1
12.0.3-beta2
13.0.1-beta1
13.0.1-beta2
3.5.8
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.5.1
4.5.10
4.5.11
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
6.0.1
6.0.1-beta1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.1
7.0.1-beta1
7.0.1-beta2
7.0.1-beta3
8.0.1
8.0.1-beta1
8.0.1-beta2
8.0.1-beta3
8.0.1-beta4
8.0.2
8.0.3
8.0.4-beta1
9.0.1
9.0.1-beta1
9.0.2-beta1
9.0.2-beta2
Fixed in
13.0.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
6.0.8
patch
|
|
6.0.7
patch
1 CVE
CVE-2024-21907
GHSA-5crp-9r3c-p9vr
Jun 22, 2022
Improper Handling of Exceptional Conditions in Newtonsoft.Json
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Newtonsoft.Json prior to version 13.0.1 is vulnerable to Insecure Defaults due to improper handling of expressions with high nesting level that lead to StackOverFlow exception or high CPU and RAM usage. Exploiting this vulnerability results in Denial Of Service (DoS). The serialization and deserialization path have different properties regarding the issue. Deserializing methods (like Serializing methods (like To mitigate the issue one either need to update Newtonsoft.Json to 13.0.1 or set
Repro code:
Additional affected product and version informationThe original statement about the problem only affecting IIS applications is misleading. Any application is affected, however the IIS has a behavior that stops restarting the instance after some time resulting in a harder-to-fix DoS.** Affected versions
10.0.1
10.0.1-beta1
10.0.2
10.0.3
11.0.1
11.0.1-beta1
11.0.1-beta2
11.0.1-beta3
11.0.2
12.0.1
12.0.1-beta1
12.0.1-beta2
+ 62 more Show less
12.0.2
12.0.2-beta1
12.0.2-beta2
12.0.2-beta3
12.0.3
12.0.3-beta1
12.0.3-beta2
13.0.1-beta1
13.0.1-beta2
3.5.8
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.5.1
4.5.10
4.5.11
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
6.0.1
6.0.1-beta1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.1
7.0.1-beta1
7.0.1-beta2
7.0.1-beta3
8.0.1
8.0.1-beta1
8.0.1-beta2
8.0.1-beta3
8.0.1-beta4
8.0.2
8.0.3
8.0.4-beta1
9.0.1
9.0.1-beta1
9.0.2-beta1
9.0.2-beta2
Fixed in
13.0.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
6.0.7
patch
|
|
6.0.6
patch
1 CVE
CVE-2024-21907
GHSA-5crp-9r3c-p9vr
Jun 22, 2022
Improper Handling of Exceptional Conditions in Newtonsoft.Json
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Newtonsoft.Json prior to version 13.0.1 is vulnerable to Insecure Defaults due to improper handling of expressions with high nesting level that lead to StackOverFlow exception or high CPU and RAM usage. Exploiting this vulnerability results in Denial Of Service (DoS). The serialization and deserialization path have different properties regarding the issue. Deserializing methods (like Serializing methods (like To mitigate the issue one either need to update Newtonsoft.Json to 13.0.1 or set
Repro code:
Additional affected product and version informationThe original statement about the problem only affecting IIS applications is misleading. Any application is affected, however the IIS has a behavior that stops restarting the instance after some time resulting in a harder-to-fix DoS.** Affected versions
10.0.1
10.0.1-beta1
10.0.2
10.0.3
11.0.1
11.0.1-beta1
11.0.1-beta2
11.0.1-beta3
11.0.2
12.0.1
12.0.1-beta1
12.0.1-beta2
+ 62 more Show less
12.0.2
12.0.2-beta1
12.0.2-beta2
12.0.2-beta3
12.0.3
12.0.3-beta1
12.0.3-beta2
13.0.1-beta1
13.0.1-beta2
3.5.8
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.5.1
4.5.10
4.5.11
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
6.0.1
6.0.1-beta1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.1
7.0.1-beta1
7.0.1-beta2
7.0.1-beta3
8.0.1
8.0.1-beta1
8.0.1-beta2
8.0.1-beta3
8.0.1-beta4
8.0.2
8.0.3
8.0.4-beta1
9.0.1
9.0.1-beta1
9.0.2-beta1
9.0.2-beta2
Fixed in
13.0.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
6.0.6
patch
|
|
6.0.5
patch
1 CVE
CVE-2024-21907
GHSA-5crp-9r3c-p9vr
Jun 22, 2022
Improper Handling of Exceptional Conditions in Newtonsoft.Json
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Newtonsoft.Json prior to version 13.0.1 is vulnerable to Insecure Defaults due to improper handling of expressions with high nesting level that lead to StackOverFlow exception or high CPU and RAM usage. Exploiting this vulnerability results in Denial Of Service (DoS). The serialization and deserialization path have different properties regarding the issue. Deserializing methods (like Serializing methods (like To mitigate the issue one either need to update Newtonsoft.Json to 13.0.1 or set
Repro code:
Additional affected product and version informationThe original statement about the problem only affecting IIS applications is misleading. Any application is affected, however the IIS has a behavior that stops restarting the instance after some time resulting in a harder-to-fix DoS.** Affected versions
10.0.1
10.0.1-beta1
10.0.2
10.0.3
11.0.1
11.0.1-beta1
11.0.1-beta2
11.0.1-beta3
11.0.2
12.0.1
12.0.1-beta1
12.0.1-beta2
+ 62 more Show less
12.0.2
12.0.2-beta1
12.0.2-beta2
12.0.2-beta3
12.0.3
12.0.3-beta1
12.0.3-beta2
13.0.1-beta1
13.0.1-beta2
3.5.8
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.5.1
4.5.10
4.5.11
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
6.0.1
6.0.1-beta1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.1
7.0.1-beta1
7.0.1-beta2
7.0.1-beta3
8.0.1
8.0.1-beta1
8.0.1-beta2
8.0.1-beta3
8.0.1-beta4
8.0.2
8.0.3
8.0.4-beta1
9.0.1
9.0.1-beta1
9.0.2-beta1
9.0.2-beta2
Fixed in
13.0.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
6.0.5
patch
|
|
6.0.4
patch
1 CVE
CVE-2024-21907
GHSA-5crp-9r3c-p9vr
Jun 22, 2022
Improper Handling of Exceptional Conditions in Newtonsoft.Json
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Newtonsoft.Json prior to version 13.0.1 is vulnerable to Insecure Defaults due to improper handling of expressions with high nesting level that lead to StackOverFlow exception or high CPU and RAM usage. Exploiting this vulnerability results in Denial Of Service (DoS). The serialization and deserialization path have different properties regarding the issue. Deserializing methods (like Serializing methods (like To mitigate the issue one either need to update Newtonsoft.Json to 13.0.1 or set
Repro code:
Additional affected product and version informationThe original statement about the problem only affecting IIS applications is misleading. Any application is affected, however the IIS has a behavior that stops restarting the instance after some time resulting in a harder-to-fix DoS.** Affected versions
10.0.1
10.0.1-beta1
10.0.2
10.0.3
11.0.1
11.0.1-beta1
11.0.1-beta2
11.0.1-beta3
11.0.2
12.0.1
12.0.1-beta1
12.0.1-beta2
+ 62 more Show less
12.0.2
12.0.2-beta1
12.0.2-beta2
12.0.2-beta3
12.0.3
12.0.3-beta1
12.0.3-beta2
13.0.1-beta1
13.0.1-beta2
3.5.8
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.5.1
4.5.10
4.5.11
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
6.0.1
6.0.1-beta1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.1
7.0.1-beta1
7.0.1-beta2
7.0.1-beta3
8.0.1
8.0.1-beta1
8.0.1-beta2
8.0.1-beta3
8.0.1-beta4
8.0.2
8.0.3
8.0.4-beta1
9.0.1
9.0.1-beta1
9.0.2-beta1
9.0.2-beta2
Fixed in
13.0.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
6.0.4
patch
|
|
6.0.3
patch
1 CVE
CVE-2024-21907
GHSA-5crp-9r3c-p9vr
Jun 22, 2022
Improper Handling of Exceptional Conditions in Newtonsoft.Json
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Newtonsoft.Json prior to version 13.0.1 is vulnerable to Insecure Defaults due to improper handling of expressions with high nesting level that lead to StackOverFlow exception or high CPU and RAM usage. Exploiting this vulnerability results in Denial Of Service (DoS). The serialization and deserialization path have different properties regarding the issue. Deserializing methods (like Serializing methods (like To mitigate the issue one either need to update Newtonsoft.Json to 13.0.1 or set
Repro code:
Additional affected product and version informationThe original statement about the problem only affecting IIS applications is misleading. Any application is affected, however the IIS has a behavior that stops restarting the instance after some time resulting in a harder-to-fix DoS.** Affected versions
10.0.1
10.0.1-beta1
10.0.2
10.0.3
11.0.1
11.0.1-beta1
11.0.1-beta2
11.0.1-beta3
11.0.2
12.0.1
12.0.1-beta1
12.0.1-beta2
+ 62 more Show less
12.0.2
12.0.2-beta1
12.0.2-beta2
12.0.2-beta3
12.0.3
12.0.3-beta1
12.0.3-beta2
13.0.1-beta1
13.0.1-beta2
3.5.8
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.5.1
4.5.10
4.5.11
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
6.0.1
6.0.1-beta1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.1
7.0.1-beta1
7.0.1-beta2
7.0.1-beta3
8.0.1
8.0.1-beta1
8.0.1-beta2
8.0.1-beta3
8.0.1-beta4
8.0.2
8.0.3
8.0.4-beta1
9.0.1
9.0.1-beta1
9.0.2-beta1
9.0.2-beta2
Fixed in
13.0.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
6.0.3
patch
|
|
6.0.2
patch
1 CVE
CVE-2024-21907
GHSA-5crp-9r3c-p9vr
Jun 22, 2022
Improper Handling of Exceptional Conditions in Newtonsoft.Json
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Newtonsoft.Json prior to version 13.0.1 is vulnerable to Insecure Defaults due to improper handling of expressions with high nesting level that lead to StackOverFlow exception or high CPU and RAM usage. Exploiting this vulnerability results in Denial Of Service (DoS). The serialization and deserialization path have different properties regarding the issue. Deserializing methods (like Serializing methods (like To mitigate the issue one either need to update Newtonsoft.Json to 13.0.1 or set
Repro code:
Additional affected product and version informationThe original statement about the problem only affecting IIS applications is misleading. Any application is affected, however the IIS has a behavior that stops restarting the instance after some time resulting in a harder-to-fix DoS.** Affected versions
10.0.1
10.0.1-beta1
10.0.2
10.0.3
11.0.1
11.0.1-beta1
11.0.1-beta2
11.0.1-beta3
11.0.2
12.0.1
12.0.1-beta1
12.0.1-beta2
+ 62 more Show less
12.0.2
12.0.2-beta1
12.0.2-beta2
12.0.2-beta3
12.0.3
12.0.3-beta1
12.0.3-beta2
13.0.1-beta1
13.0.1-beta2
3.5.8
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.5.1
4.5.10
4.5.11
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
6.0.1
6.0.1-beta1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.1
7.0.1-beta1
7.0.1-beta2
7.0.1-beta3
8.0.1
8.0.1-beta1
8.0.1-beta2
8.0.1-beta3
8.0.1-beta4
8.0.2
8.0.3
8.0.4-beta1
9.0.1
9.0.1-beta1
9.0.2-beta1
9.0.2-beta2
Fixed in
13.0.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
6.0.2
patch
|
|
6.0.1
major
1 CVE
CVE-2024-21907
GHSA-5crp-9r3c-p9vr
Jun 22, 2022
Improper Handling of Exceptional Conditions in Newtonsoft.Json
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Newtonsoft.Json prior to version 13.0.1 is vulnerable to Insecure Defaults due to improper handling of expressions with high nesting level that lead to StackOverFlow exception or high CPU and RAM usage. Exploiting this vulnerability results in Denial Of Service (DoS). The serialization and deserialization path have different properties regarding the issue. Deserializing methods (like Serializing methods (like To mitigate the issue one either need to update Newtonsoft.Json to 13.0.1 or set
Repro code:
Additional affected product and version informationThe original statement about the problem only affecting IIS applications is misleading. Any application is affected, however the IIS has a behavior that stops restarting the instance after some time resulting in a harder-to-fix DoS.** Affected versions
10.0.1
10.0.1-beta1
10.0.2
10.0.3
11.0.1
11.0.1-beta1
11.0.1-beta2
11.0.1-beta3
11.0.2
12.0.1
12.0.1-beta1
12.0.1-beta2
+ 62 more Show less
12.0.2
12.0.2-beta1
12.0.2-beta2
12.0.2-beta3
12.0.3
12.0.3-beta1
12.0.3-beta2
13.0.1-beta1
13.0.1-beta2
3.5.8
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.5.1
4.5.10
4.5.11
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
6.0.1
6.0.1-beta1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.1
7.0.1-beta1
7.0.1-beta2
7.0.1-beta3
8.0.1
8.0.1-beta1
8.0.1-beta2
8.0.1-beta3
8.0.1-beta4
8.0.2
8.0.3
8.0.4-beta1
9.0.1
9.0.1-beta1
9.0.2-beta1
9.0.2-beta2
Fixed in
13.0.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
6.0.1
major
|
|
5.0.8
patch
1 CVE
CVE-2024-21907
GHSA-5crp-9r3c-p9vr
Jun 22, 2022
Improper Handling of Exceptional Conditions in Newtonsoft.Json
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Newtonsoft.Json prior to version 13.0.1 is vulnerable to Insecure Defaults due to improper handling of expressions with high nesting level that lead to StackOverFlow exception or high CPU and RAM usage. Exploiting this vulnerability results in Denial Of Service (DoS). The serialization and deserialization path have different properties regarding the issue. Deserializing methods (like Serializing methods (like To mitigate the issue one either need to update Newtonsoft.Json to 13.0.1 or set
Repro code:
Additional affected product and version informationThe original statement about the problem only affecting IIS applications is misleading. Any application is affected, however the IIS has a behavior that stops restarting the instance after some time resulting in a harder-to-fix DoS.** Affected versions
10.0.1
10.0.1-beta1
10.0.2
10.0.3
11.0.1
11.0.1-beta1
11.0.1-beta2
11.0.1-beta3
11.0.2
12.0.1
12.0.1-beta1
12.0.1-beta2
+ 62 more Show less
12.0.2
12.0.2-beta1
12.0.2-beta2
12.0.2-beta3
12.0.3
12.0.3-beta1
12.0.3-beta2
13.0.1-beta1
13.0.1-beta2
3.5.8
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.5.1
4.5.10
4.5.11
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
6.0.1
6.0.1-beta1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.1
7.0.1-beta1
7.0.1-beta2
7.0.1-beta3
8.0.1
8.0.1-beta1
8.0.1-beta2
8.0.1-beta3
8.0.1-beta4
8.0.2
8.0.3
8.0.4-beta1
9.0.1
9.0.1-beta1
9.0.2-beta1
9.0.2-beta2
Fixed in
13.0.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
5.0.8
patch
|
|
5.0.7
patch
1 CVE
CVE-2024-21907
GHSA-5crp-9r3c-p9vr
Jun 22, 2022
Improper Handling of Exceptional Conditions in Newtonsoft.Json
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Newtonsoft.Json prior to version 13.0.1 is vulnerable to Insecure Defaults due to improper handling of expressions with high nesting level that lead to StackOverFlow exception or high CPU and RAM usage. Exploiting this vulnerability results in Denial Of Service (DoS). The serialization and deserialization path have different properties regarding the issue. Deserializing methods (like Serializing methods (like To mitigate the issue one either need to update Newtonsoft.Json to 13.0.1 or set
Repro code:
Additional affected product and version informationThe original statement about the problem only affecting IIS applications is misleading. Any application is affected, however the IIS has a behavior that stops restarting the instance after some time resulting in a harder-to-fix DoS.** Affected versions
10.0.1
10.0.1-beta1
10.0.2
10.0.3
11.0.1
11.0.1-beta1
11.0.1-beta2
11.0.1-beta3
11.0.2
12.0.1
12.0.1-beta1
12.0.1-beta2
+ 62 more Show less
12.0.2
12.0.2-beta1
12.0.2-beta2
12.0.2-beta3
12.0.3
12.0.3-beta1
12.0.3-beta2
13.0.1-beta1
13.0.1-beta2
3.5.8
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.5.1
4.5.10
4.5.11
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
6.0.1
6.0.1-beta1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.1
7.0.1-beta1
7.0.1-beta2
7.0.1-beta3
8.0.1
8.0.1-beta1
8.0.1-beta2
8.0.1-beta3
8.0.1-beta4
8.0.2
8.0.3
8.0.4-beta1
9.0.1
9.0.1-beta1
9.0.2-beta1
9.0.2-beta2
Fixed in
13.0.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
5.0.7
patch
|
|
5.0.6
patch
1 CVE
CVE-2024-21907
GHSA-5crp-9r3c-p9vr
Jun 22, 2022
Improper Handling of Exceptional Conditions in Newtonsoft.Json
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Newtonsoft.Json prior to version 13.0.1 is vulnerable to Insecure Defaults due to improper handling of expressions with high nesting level that lead to StackOverFlow exception or high CPU and RAM usage. Exploiting this vulnerability results in Denial Of Service (DoS). The serialization and deserialization path have different properties regarding the issue. Deserializing methods (like Serializing methods (like To mitigate the issue one either need to update Newtonsoft.Json to 13.0.1 or set
Repro code:
Additional affected product and version informationThe original statement about the problem only affecting IIS applications is misleading. Any application is affected, however the IIS has a behavior that stops restarting the instance after some time resulting in a harder-to-fix DoS.** Affected versions
10.0.1
10.0.1-beta1
10.0.2
10.0.3
11.0.1
11.0.1-beta1
11.0.1-beta2
11.0.1-beta3
11.0.2
12.0.1
12.0.1-beta1
12.0.1-beta2
+ 62 more Show less
12.0.2
12.0.2-beta1
12.0.2-beta2
12.0.2-beta3
12.0.3
12.0.3-beta1
12.0.3-beta2
13.0.1-beta1
13.0.1-beta2
3.5.8
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.5.1
4.5.10
4.5.11
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
6.0.1
6.0.1-beta1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.1
7.0.1-beta1
7.0.1-beta2
7.0.1-beta3
8.0.1
8.0.1-beta1
8.0.1-beta2
8.0.1-beta3
8.0.1-beta4
8.0.2
8.0.3
8.0.4-beta1
9.0.1
9.0.1-beta1
9.0.2-beta1
9.0.2-beta2
Fixed in
13.0.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
5.0.6
patch
|
|
5.0.5
patch
1 CVE
CVE-2024-21907
GHSA-5crp-9r3c-p9vr
Jun 22, 2022
Improper Handling of Exceptional Conditions in Newtonsoft.Json
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Newtonsoft.Json prior to version 13.0.1 is vulnerable to Insecure Defaults due to improper handling of expressions with high nesting level that lead to StackOverFlow exception or high CPU and RAM usage. Exploiting this vulnerability results in Denial Of Service (DoS). The serialization and deserialization path have different properties regarding the issue. Deserializing methods (like Serializing methods (like To mitigate the issue one either need to update Newtonsoft.Json to 13.0.1 or set
Repro code:
Additional affected product and version informationThe original statement about the problem only affecting IIS applications is misleading. Any application is affected, however the IIS has a behavior that stops restarting the instance after some time resulting in a harder-to-fix DoS.** Affected versions
10.0.1
10.0.1-beta1
10.0.2
10.0.3
11.0.1
11.0.1-beta1
11.0.1-beta2
11.0.1-beta3
11.0.2
12.0.1
12.0.1-beta1
12.0.1-beta2
+ 62 more Show less
12.0.2
12.0.2-beta1
12.0.2-beta2
12.0.2-beta3
12.0.3
12.0.3-beta1
12.0.3-beta2
13.0.1-beta1
13.0.1-beta2
3.5.8
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.5.1
4.5.10
4.5.11
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
6.0.1
6.0.1-beta1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.1
7.0.1-beta1
7.0.1-beta2
7.0.1-beta3
8.0.1
8.0.1-beta1
8.0.1-beta2
8.0.1-beta3
8.0.1-beta4
8.0.2
8.0.3
8.0.4-beta1
9.0.1
9.0.1-beta1
9.0.2-beta1
9.0.2-beta2
Fixed in
13.0.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
5.0.5
patch
|
|
5.0.4
patch
1 CVE
CVE-2024-21907
GHSA-5crp-9r3c-p9vr
Jun 22, 2022
Improper Handling of Exceptional Conditions in Newtonsoft.Json
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Newtonsoft.Json prior to version 13.0.1 is vulnerable to Insecure Defaults due to improper handling of expressions with high nesting level that lead to StackOverFlow exception or high CPU and RAM usage. Exploiting this vulnerability results in Denial Of Service (DoS). The serialization and deserialization path have different properties regarding the issue. Deserializing methods (like Serializing methods (like To mitigate the issue one either need to update Newtonsoft.Json to 13.0.1 or set
Repro code:
Additional affected product and version informationThe original statement about the problem only affecting IIS applications is misleading. Any application is affected, however the IIS has a behavior that stops restarting the instance after some time resulting in a harder-to-fix DoS.** Affected versions
10.0.1
10.0.1-beta1
10.0.2
10.0.3
11.0.1
11.0.1-beta1
11.0.1-beta2
11.0.1-beta3
11.0.2
12.0.1
12.0.1-beta1
12.0.1-beta2
+ 62 more Show less
12.0.2
12.0.2-beta1
12.0.2-beta2
12.0.2-beta3
12.0.3
12.0.3-beta1
12.0.3-beta2
13.0.1-beta1
13.0.1-beta2
3.5.8
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.5.1
4.5.10
4.5.11
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
6.0.1
6.0.1-beta1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.1
7.0.1-beta1
7.0.1-beta2
7.0.1-beta3
8.0.1
8.0.1-beta1
8.0.1-beta2
8.0.1-beta3
8.0.1-beta4
8.0.2
8.0.3
8.0.4-beta1
9.0.1
9.0.1-beta1
9.0.2-beta1
9.0.2-beta2
Fixed in
13.0.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
5.0.4
patch
|
|
5.0.3
patch
1 CVE
CVE-2024-21907
GHSA-5crp-9r3c-p9vr
Jun 22, 2022
Improper Handling of Exceptional Conditions in Newtonsoft.Json
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Newtonsoft.Json prior to version 13.0.1 is vulnerable to Insecure Defaults due to improper handling of expressions with high nesting level that lead to StackOverFlow exception or high CPU and RAM usage. Exploiting this vulnerability results in Denial Of Service (DoS). The serialization and deserialization path have different properties regarding the issue. Deserializing methods (like Serializing methods (like To mitigate the issue one either need to update Newtonsoft.Json to 13.0.1 or set
Repro code:
Additional affected product and version informationThe original statement about the problem only affecting IIS applications is misleading. Any application is affected, however the IIS has a behavior that stops restarting the instance after some time resulting in a harder-to-fix DoS.** Affected versions
10.0.1
10.0.1-beta1
10.0.2
10.0.3
11.0.1
11.0.1-beta1
11.0.1-beta2
11.0.1-beta3
11.0.2
12.0.1
12.0.1-beta1
12.0.1-beta2
+ 62 more Show less
12.0.2
12.0.2-beta1
12.0.2-beta2
12.0.2-beta3
12.0.3
12.0.3-beta1
12.0.3-beta2
13.0.1-beta1
13.0.1-beta2
3.5.8
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.5.1
4.5.10
4.5.11
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
6.0.1
6.0.1-beta1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.1
7.0.1-beta1
7.0.1-beta2
7.0.1-beta3
8.0.1
8.0.1-beta1
8.0.1-beta2
8.0.1-beta3
8.0.1-beta4
8.0.2
8.0.3
8.0.4-beta1
9.0.1
9.0.1-beta1
9.0.2-beta1
9.0.2-beta2
Fixed in
13.0.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
5.0.3
patch
|
|
5.0.2
patch
1 CVE
CVE-2024-21907
GHSA-5crp-9r3c-p9vr
Jun 22, 2022
Improper Handling of Exceptional Conditions in Newtonsoft.Json
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Newtonsoft.Json prior to version 13.0.1 is vulnerable to Insecure Defaults due to improper handling of expressions with high nesting level that lead to StackOverFlow exception or high CPU and RAM usage. Exploiting this vulnerability results in Denial Of Service (DoS). The serialization and deserialization path have different properties regarding the issue. Deserializing methods (like Serializing methods (like To mitigate the issue one either need to update Newtonsoft.Json to 13.0.1 or set
Repro code:
Additional affected product and version informationThe original statement about the problem only affecting IIS applications is misleading. Any application is affected, however the IIS has a behavior that stops restarting the instance after some time resulting in a harder-to-fix DoS.** Affected versions
10.0.1
10.0.1-beta1
10.0.2
10.0.3
11.0.1
11.0.1-beta1
11.0.1-beta2
11.0.1-beta3
11.0.2
12.0.1
12.0.1-beta1
12.0.1-beta2
+ 62 more Show less
12.0.2
12.0.2-beta1
12.0.2-beta2
12.0.2-beta3
12.0.3
12.0.3-beta1
12.0.3-beta2
13.0.1-beta1
13.0.1-beta2
3.5.8
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.5.1
4.5.10
4.5.11
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
6.0.1
6.0.1-beta1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.1
7.0.1-beta1
7.0.1-beta2
7.0.1-beta3
8.0.1
8.0.1-beta1
8.0.1-beta2
8.0.1-beta3
8.0.1-beta4
8.0.2
8.0.3
8.0.4-beta1
9.0.1
9.0.1-beta1
9.0.2-beta1
9.0.2-beta2
Fixed in
13.0.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
5.0.2
patch
|
|
5.0.1
major
1 CVE
CVE-2024-21907
GHSA-5crp-9r3c-p9vr
Jun 22, 2022
Improper Handling of Exceptional Conditions in Newtonsoft.Json
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Newtonsoft.Json prior to version 13.0.1 is vulnerable to Insecure Defaults due to improper handling of expressions with high nesting level that lead to StackOverFlow exception or high CPU and RAM usage. Exploiting this vulnerability results in Denial Of Service (DoS). The serialization and deserialization path have different properties regarding the issue. Deserializing methods (like Serializing methods (like To mitigate the issue one either need to update Newtonsoft.Json to 13.0.1 or set
Repro code:
Additional affected product and version informationThe original statement about the problem only affecting IIS applications is misleading. Any application is affected, however the IIS has a behavior that stops restarting the instance after some time resulting in a harder-to-fix DoS.** Affected versions
10.0.1
10.0.1-beta1
10.0.2
10.0.3
11.0.1
11.0.1-beta1
11.0.1-beta2
11.0.1-beta3
11.0.2
12.0.1
12.0.1-beta1
12.0.1-beta2
+ 62 more Show less
12.0.2
12.0.2-beta1
12.0.2-beta2
12.0.2-beta3
12.0.3
12.0.3-beta1
12.0.3-beta2
13.0.1-beta1
13.0.1-beta2
3.5.8
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.5.1
4.5.10
4.5.11
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
6.0.1
6.0.1-beta1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.1
7.0.1-beta1
7.0.1-beta2
7.0.1-beta3
8.0.1
8.0.1-beta1
8.0.1-beta2
8.0.1-beta3
8.0.1-beta4
8.0.2
8.0.3
8.0.4-beta1
9.0.1
9.0.1-beta1
9.0.2-beta1
9.0.2-beta2
Fixed in
13.0.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
5.0.1
major
|
|
4.5.11
patch
1 CVE
CVE-2024-21907
GHSA-5crp-9r3c-p9vr
Jun 22, 2022
Improper Handling of Exceptional Conditions in Newtonsoft.Json
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Newtonsoft.Json prior to version 13.0.1 is vulnerable to Insecure Defaults due to improper handling of expressions with high nesting level that lead to StackOverFlow exception or high CPU and RAM usage. Exploiting this vulnerability results in Denial Of Service (DoS). The serialization and deserialization path have different properties regarding the issue. Deserializing methods (like Serializing methods (like To mitigate the issue one either need to update Newtonsoft.Json to 13.0.1 or set
Repro code:
Additional affected product and version informationThe original statement about the problem only affecting IIS applications is misleading. Any application is affected, however the IIS has a behavior that stops restarting the instance after some time resulting in a harder-to-fix DoS.** Affected versions
10.0.1
10.0.1-beta1
10.0.2
10.0.3
11.0.1
11.0.1-beta1
11.0.1-beta2
11.0.1-beta3
11.0.2
12.0.1
12.0.1-beta1
12.0.1-beta2
+ 62 more Show less
12.0.2
12.0.2-beta1
12.0.2-beta2
12.0.2-beta3
12.0.3
12.0.3-beta1
12.0.3-beta2
13.0.1-beta1
13.0.1-beta2
3.5.8
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.5.1
4.5.10
4.5.11
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
6.0.1
6.0.1-beta1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.1
7.0.1-beta1
7.0.1-beta2
7.0.1-beta3
8.0.1
8.0.1-beta1
8.0.1-beta2
8.0.1-beta3
8.0.1-beta4
8.0.2
8.0.3
8.0.4-beta1
9.0.1
9.0.1-beta1
9.0.2-beta1
9.0.2-beta2
Fixed in
13.0.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
4.5.11
patch
|
|
4.5.10
patch
1 CVE
CVE-2024-21907
GHSA-5crp-9r3c-p9vr
Jun 22, 2022
Improper Handling of Exceptional Conditions in Newtonsoft.Json
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Newtonsoft.Json prior to version 13.0.1 is vulnerable to Insecure Defaults due to improper handling of expressions with high nesting level that lead to StackOverFlow exception or high CPU and RAM usage. Exploiting this vulnerability results in Denial Of Service (DoS). The serialization and deserialization path have different properties regarding the issue. Deserializing methods (like Serializing methods (like To mitigate the issue one either need to update Newtonsoft.Json to 13.0.1 or set
Repro code:
Additional affected product and version informationThe original statement about the problem only affecting IIS applications is misleading. Any application is affected, however the IIS has a behavior that stops restarting the instance after some time resulting in a harder-to-fix DoS.** Affected versions
10.0.1
10.0.1-beta1
10.0.2
10.0.3
11.0.1
11.0.1-beta1
11.0.1-beta2
11.0.1-beta3
11.0.2
12.0.1
12.0.1-beta1
12.0.1-beta2
+ 62 more Show less
12.0.2
12.0.2-beta1
12.0.2-beta2
12.0.2-beta3
12.0.3
12.0.3-beta1
12.0.3-beta2
13.0.1-beta1
13.0.1-beta2
3.5.8
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.5.1
4.5.10
4.5.11
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
6.0.1
6.0.1-beta1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.1
7.0.1-beta1
7.0.1-beta2
7.0.1-beta3
8.0.1
8.0.1-beta1
8.0.1-beta2
8.0.1-beta3
8.0.1-beta4
8.0.2
8.0.3
8.0.4-beta1
9.0.1
9.0.1-beta1
9.0.2-beta1
9.0.2-beta2
Fixed in
13.0.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
4.5.10
patch
|
|
4.5.9
patch
1 CVE
CVE-2024-21907
GHSA-5crp-9r3c-p9vr
Jun 22, 2022
Improper Handling of Exceptional Conditions in Newtonsoft.Json
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Newtonsoft.Json prior to version 13.0.1 is vulnerable to Insecure Defaults due to improper handling of expressions with high nesting level that lead to StackOverFlow exception or high CPU and RAM usage. Exploiting this vulnerability results in Denial Of Service (DoS). The serialization and deserialization path have different properties regarding the issue. Deserializing methods (like Serializing methods (like To mitigate the issue one either need to update Newtonsoft.Json to 13.0.1 or set
Repro code:
Additional affected product and version informationThe original statement about the problem only affecting IIS applications is misleading. Any application is affected, however the IIS has a behavior that stops restarting the instance after some time resulting in a harder-to-fix DoS.** Affected versions
10.0.1
10.0.1-beta1
10.0.2
10.0.3
11.0.1
11.0.1-beta1
11.0.1-beta2
11.0.1-beta3
11.0.2
12.0.1
12.0.1-beta1
12.0.1-beta2
+ 62 more Show less
12.0.2
12.0.2-beta1
12.0.2-beta2
12.0.2-beta3
12.0.3
12.0.3-beta1
12.0.3-beta2
13.0.1-beta1
13.0.1-beta2
3.5.8
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.5.1
4.5.10
4.5.11
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
6.0.1
6.0.1-beta1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.1
7.0.1-beta1
7.0.1-beta2
7.0.1-beta3
8.0.1
8.0.1-beta1
8.0.1-beta2
8.0.1-beta3
8.0.1-beta4
8.0.2
8.0.3
8.0.4-beta1
9.0.1
9.0.1-beta1
9.0.2-beta1
9.0.2-beta2
Fixed in
13.0.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
4.5.9
patch
|
|
4.5.8
patch
1 CVE
CVE-2024-21907
GHSA-5crp-9r3c-p9vr
Jun 22, 2022
Improper Handling of Exceptional Conditions in Newtonsoft.Json
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Newtonsoft.Json prior to version 13.0.1 is vulnerable to Insecure Defaults due to improper handling of expressions with high nesting level that lead to StackOverFlow exception or high CPU and RAM usage. Exploiting this vulnerability results in Denial Of Service (DoS). The serialization and deserialization path have different properties regarding the issue. Deserializing methods (like Serializing methods (like To mitigate the issue one either need to update Newtonsoft.Json to 13.0.1 or set
Repro code:
Additional affected product and version informationThe original statement about the problem only affecting IIS applications is misleading. Any application is affected, however the IIS has a behavior that stops restarting the instance after some time resulting in a harder-to-fix DoS.** Affected versions
10.0.1
10.0.1-beta1
10.0.2
10.0.3
11.0.1
11.0.1-beta1
11.0.1-beta2
11.0.1-beta3
11.0.2
12.0.1
12.0.1-beta1
12.0.1-beta2
+ 62 more Show less
12.0.2
12.0.2-beta1
12.0.2-beta2
12.0.2-beta3
12.0.3
12.0.3-beta1
12.0.3-beta2
13.0.1-beta1
13.0.1-beta2
3.5.8
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.5.1
4.5.10
4.5.11
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
6.0.1
6.0.1-beta1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.1
7.0.1-beta1
7.0.1-beta2
7.0.1-beta3
8.0.1
8.0.1-beta1
8.0.1-beta2
8.0.1-beta3
8.0.1-beta4
8.0.2
8.0.3
8.0.4-beta1
9.0.1
9.0.1-beta1
9.0.2-beta1
9.0.2-beta2
Fixed in
13.0.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
4.5.8
patch
|
|
4.5.7
patch
1 CVE
CVE-2024-21907
GHSA-5crp-9r3c-p9vr
Jun 22, 2022
Improper Handling of Exceptional Conditions in Newtonsoft.Json
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Newtonsoft.Json prior to version 13.0.1 is vulnerable to Insecure Defaults due to improper handling of expressions with high nesting level that lead to StackOverFlow exception or high CPU and RAM usage. Exploiting this vulnerability results in Denial Of Service (DoS). The serialization and deserialization path have different properties regarding the issue. Deserializing methods (like Serializing methods (like To mitigate the issue one either need to update Newtonsoft.Json to 13.0.1 or set
Repro code:
Additional affected product and version informationThe original statement about the problem only affecting IIS applications is misleading. Any application is affected, however the IIS has a behavior that stops restarting the instance after some time resulting in a harder-to-fix DoS.** Affected versions
10.0.1
10.0.1-beta1
10.0.2
10.0.3
11.0.1
11.0.1-beta1
11.0.1-beta2
11.0.1-beta3
11.0.2
12.0.1
12.0.1-beta1
12.0.1-beta2
+ 62 more Show less
12.0.2
12.0.2-beta1
12.0.2-beta2
12.0.2-beta3
12.0.3
12.0.3-beta1
12.0.3-beta2
13.0.1-beta1
13.0.1-beta2
3.5.8
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.5.1
4.5.10
4.5.11
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
6.0.1
6.0.1-beta1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.1
7.0.1-beta1
7.0.1-beta2
7.0.1-beta3
8.0.1
8.0.1-beta1
8.0.1-beta2
8.0.1-beta3
8.0.1-beta4
8.0.2
8.0.3
8.0.4-beta1
9.0.1
9.0.1-beta1
9.0.2-beta1
9.0.2-beta2
Fixed in
13.0.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
4.5.7
patch
|
|
4.5.6
patch
1 CVE
CVE-2024-21907
GHSA-5crp-9r3c-p9vr
Jun 22, 2022
Improper Handling of Exceptional Conditions in Newtonsoft.Json
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Newtonsoft.Json prior to version 13.0.1 is vulnerable to Insecure Defaults due to improper handling of expressions with high nesting level that lead to StackOverFlow exception or high CPU and RAM usage. Exploiting this vulnerability results in Denial Of Service (DoS). The serialization and deserialization path have different properties regarding the issue. Deserializing methods (like Serializing methods (like To mitigate the issue one either need to update Newtonsoft.Json to 13.0.1 or set
Repro code:
Additional affected product and version informationThe original statement about the problem only affecting IIS applications is misleading. Any application is affected, however the IIS has a behavior that stops restarting the instance after some time resulting in a harder-to-fix DoS.** Affected versions
10.0.1
10.0.1-beta1
10.0.2
10.0.3
11.0.1
11.0.1-beta1
11.0.1-beta2
11.0.1-beta3
11.0.2
12.0.1
12.0.1-beta1
12.0.1-beta2
+ 62 more Show less
12.0.2
12.0.2-beta1
12.0.2-beta2
12.0.2-beta3
12.0.3
12.0.3-beta1
12.0.3-beta2
13.0.1-beta1
13.0.1-beta2
3.5.8
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.5.1
4.5.10
4.5.11
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
6.0.1
6.0.1-beta1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.1
7.0.1-beta1
7.0.1-beta2
7.0.1-beta3
8.0.1
8.0.1-beta1
8.0.1-beta2
8.0.1-beta3
8.0.1-beta4
8.0.2
8.0.3
8.0.4-beta1
9.0.1
9.0.1-beta1
9.0.2-beta1
9.0.2-beta2
Fixed in
13.0.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
4.5.6
patch
|
|
4.5.5
patch
1 CVE
CVE-2024-21907
GHSA-5crp-9r3c-p9vr
Jun 22, 2022
Improper Handling of Exceptional Conditions in Newtonsoft.Json
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Newtonsoft.Json prior to version 13.0.1 is vulnerable to Insecure Defaults due to improper handling of expressions with high nesting level that lead to StackOverFlow exception or high CPU and RAM usage. Exploiting this vulnerability results in Denial Of Service (DoS). The serialization and deserialization path have different properties regarding the issue. Deserializing methods (like Serializing methods (like To mitigate the issue one either need to update Newtonsoft.Json to 13.0.1 or set
Repro code:
Additional affected product and version informationThe original statement about the problem only affecting IIS applications is misleading. Any application is affected, however the IIS has a behavior that stops restarting the instance after some time resulting in a harder-to-fix DoS.** Affected versions
10.0.1
10.0.1-beta1
10.0.2
10.0.3
11.0.1
11.0.1-beta1
11.0.1-beta2
11.0.1-beta3
11.0.2
12.0.1
12.0.1-beta1
12.0.1-beta2
+ 62 more Show less
12.0.2
12.0.2-beta1
12.0.2-beta2
12.0.2-beta3
12.0.3
12.0.3-beta1
12.0.3-beta2
13.0.1-beta1
13.0.1-beta2
3.5.8
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.5.1
4.5.10
4.5.11
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
6.0.1
6.0.1-beta1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.1
7.0.1-beta1
7.0.1-beta2
7.0.1-beta3
8.0.1
8.0.1-beta1
8.0.1-beta2
8.0.1-beta3
8.0.1-beta4
8.0.2
8.0.3
8.0.4-beta1
9.0.1
9.0.1-beta1
9.0.2-beta1
9.0.2-beta2
Fixed in
13.0.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
4.5.5
patch
|
|
4.5.4
patch
1 CVE
CVE-2024-21907
GHSA-5crp-9r3c-p9vr
Jun 22, 2022
Improper Handling of Exceptional Conditions in Newtonsoft.Json
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Newtonsoft.Json prior to version 13.0.1 is vulnerable to Insecure Defaults due to improper handling of expressions with high nesting level that lead to StackOverFlow exception or high CPU and RAM usage. Exploiting this vulnerability results in Denial Of Service (DoS). The serialization and deserialization path have different properties regarding the issue. Deserializing methods (like Serializing methods (like To mitigate the issue one either need to update Newtonsoft.Json to 13.0.1 or set
Repro code:
Additional affected product and version informationThe original statement about the problem only affecting IIS applications is misleading. Any application is affected, however the IIS has a behavior that stops restarting the instance after some time resulting in a harder-to-fix DoS.** Affected versions
10.0.1
10.0.1-beta1
10.0.2
10.0.3
11.0.1
11.0.1-beta1
11.0.1-beta2
11.0.1-beta3
11.0.2
12.0.1
12.0.1-beta1
12.0.1-beta2
+ 62 more Show less
12.0.2
12.0.2-beta1
12.0.2-beta2
12.0.2-beta3
12.0.3
12.0.3-beta1
12.0.3-beta2
13.0.1-beta1
13.0.1-beta2
3.5.8
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.5.1
4.5.10
4.5.11
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
6.0.1
6.0.1-beta1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.1
7.0.1-beta1
7.0.1-beta2
7.0.1-beta3
8.0.1
8.0.1-beta1
8.0.1-beta2
8.0.1-beta3
8.0.1-beta4
8.0.2
8.0.3
8.0.4-beta1
9.0.1
9.0.1-beta1
9.0.2-beta1
9.0.2-beta2
Fixed in
13.0.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
4.5.4
patch
|
|
4.5.3
patch
1 CVE
CVE-2024-21907
GHSA-5crp-9r3c-p9vr
Jun 22, 2022
Improper Handling of Exceptional Conditions in Newtonsoft.Json
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Newtonsoft.Json prior to version 13.0.1 is vulnerable to Insecure Defaults due to improper handling of expressions with high nesting level that lead to StackOverFlow exception or high CPU and RAM usage. Exploiting this vulnerability results in Denial Of Service (DoS). The serialization and deserialization path have different properties regarding the issue. Deserializing methods (like Serializing methods (like To mitigate the issue one either need to update Newtonsoft.Json to 13.0.1 or set
Repro code:
Additional affected product and version informationThe original statement about the problem only affecting IIS applications is misleading. Any application is affected, however the IIS has a behavior that stops restarting the instance after some time resulting in a harder-to-fix DoS.** Affected versions
10.0.1
10.0.1-beta1
10.0.2
10.0.3
11.0.1
11.0.1-beta1
11.0.1-beta2
11.0.1-beta3
11.0.2
12.0.1
12.0.1-beta1
12.0.1-beta2
+ 62 more Show less
12.0.2
12.0.2-beta1
12.0.2-beta2
12.0.2-beta3
12.0.3
12.0.3-beta1
12.0.3-beta2
13.0.1-beta1
13.0.1-beta2
3.5.8
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.5.1
4.5.10
4.5.11
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
6.0.1
6.0.1-beta1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.1
7.0.1-beta1
7.0.1-beta2
7.0.1-beta3
8.0.1
8.0.1-beta1
8.0.1-beta2
8.0.1-beta3
8.0.1-beta4
8.0.2
8.0.3
8.0.4-beta1
9.0.1
9.0.1-beta1
9.0.2-beta1
9.0.2-beta2
Fixed in
13.0.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
4.5.3
patch
|
|
4.5.2
patch
1 CVE
CVE-2024-21907
GHSA-5crp-9r3c-p9vr
Jun 22, 2022
Improper Handling of Exceptional Conditions in Newtonsoft.Json
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Newtonsoft.Json prior to version 13.0.1 is vulnerable to Insecure Defaults due to improper handling of expressions with high nesting level that lead to StackOverFlow exception or high CPU and RAM usage. Exploiting this vulnerability results in Denial Of Service (DoS). The serialization and deserialization path have different properties regarding the issue. Deserializing methods (like Serializing methods (like To mitigate the issue one either need to update Newtonsoft.Json to 13.0.1 or set
Repro code:
Additional affected product and version informationThe original statement about the problem only affecting IIS applications is misleading. Any application is affected, however the IIS has a behavior that stops restarting the instance after some time resulting in a harder-to-fix DoS.** Affected versions
10.0.1
10.0.1-beta1
10.0.2
10.0.3
11.0.1
11.0.1-beta1
11.0.1-beta2
11.0.1-beta3
11.0.2
12.0.1
12.0.1-beta1
12.0.1-beta2
+ 62 more Show less
12.0.2
12.0.2-beta1
12.0.2-beta2
12.0.2-beta3
12.0.3
12.0.3-beta1
12.0.3-beta2
13.0.1-beta1
13.0.1-beta2
3.5.8
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.5.1
4.5.10
4.5.11
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
6.0.1
6.0.1-beta1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.1
7.0.1-beta1
7.0.1-beta2
7.0.1-beta3
8.0.1
8.0.1-beta1
8.0.1-beta2
8.0.1-beta3
8.0.1-beta4
8.0.2
8.0.3
8.0.4-beta1
9.0.1
9.0.1-beta1
9.0.2-beta1
9.0.2-beta2
Fixed in
13.0.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
4.5.2
patch
|
|
4.5.1
minor
1 CVE
CVE-2024-21907
GHSA-5crp-9r3c-p9vr
Jun 22, 2022
Improper Handling of Exceptional Conditions in Newtonsoft.Json
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Newtonsoft.Json prior to version 13.0.1 is vulnerable to Insecure Defaults due to improper handling of expressions with high nesting level that lead to StackOverFlow exception or high CPU and RAM usage. Exploiting this vulnerability results in Denial Of Service (DoS). The serialization and deserialization path have different properties regarding the issue. Deserializing methods (like Serializing methods (like To mitigate the issue one either need to update Newtonsoft.Json to 13.0.1 or set
Repro code:
Additional affected product and version informationThe original statement about the problem only affecting IIS applications is misleading. Any application is affected, however the IIS has a behavior that stops restarting the instance after some time resulting in a harder-to-fix DoS.** Affected versions
10.0.1
10.0.1-beta1
10.0.2
10.0.3
11.0.1
11.0.1-beta1
11.0.1-beta2
11.0.1-beta3
11.0.2
12.0.1
12.0.1-beta1
12.0.1-beta2
+ 62 more Show less
12.0.2
12.0.2-beta1
12.0.2-beta2
12.0.2-beta3
12.0.3
12.0.3-beta1
12.0.3-beta2
13.0.1-beta1
13.0.1-beta2
3.5.8
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.5.1
4.5.10
4.5.11
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
6.0.1
6.0.1-beta1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.1
7.0.1-beta1
7.0.1-beta2
7.0.1-beta3
8.0.1
8.0.1-beta1
8.0.1-beta2
8.0.1-beta3
8.0.1-beta4
8.0.2
8.0.3
8.0.4-beta1
9.0.1
9.0.1-beta1
9.0.2-beta1
9.0.2-beta2
Fixed in
13.0.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
4.5.1
minor
|
|
4.0.8
patch
1 CVE
CVE-2024-21907
GHSA-5crp-9r3c-p9vr
Jun 22, 2022
Improper Handling of Exceptional Conditions in Newtonsoft.Json
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Newtonsoft.Json prior to version 13.0.1 is vulnerable to Insecure Defaults due to improper handling of expressions with high nesting level that lead to StackOverFlow exception or high CPU and RAM usage. Exploiting this vulnerability results in Denial Of Service (DoS). The serialization and deserialization path have different properties regarding the issue. Deserializing methods (like Serializing methods (like To mitigate the issue one either need to update Newtonsoft.Json to 13.0.1 or set
Repro code:
Additional affected product and version informationThe original statement about the problem only affecting IIS applications is misleading. Any application is affected, however the IIS has a behavior that stops restarting the instance after some time resulting in a harder-to-fix DoS.** Affected versions
10.0.1
10.0.1-beta1
10.0.2
10.0.3
11.0.1
11.0.1-beta1
11.0.1-beta2
11.0.1-beta3
11.0.2
12.0.1
12.0.1-beta1
12.0.1-beta2
+ 62 more Show less
12.0.2
12.0.2-beta1
12.0.2-beta2
12.0.2-beta3
12.0.3
12.0.3-beta1
12.0.3-beta2
13.0.1-beta1
13.0.1-beta2
3.5.8
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.5.1
4.5.10
4.5.11
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
6.0.1
6.0.1-beta1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.1
7.0.1-beta1
7.0.1-beta2
7.0.1-beta3
8.0.1
8.0.1-beta1
8.0.1-beta2
8.0.1-beta3
8.0.1-beta4
8.0.2
8.0.3
8.0.4-beta1
9.0.1
9.0.1-beta1
9.0.2-beta1
9.0.2-beta2
Fixed in
13.0.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
4.0.8
patch
|
|
4.0.7
patch
1 CVE
CVE-2024-21907
GHSA-5crp-9r3c-p9vr
Jun 22, 2022
Improper Handling of Exceptional Conditions in Newtonsoft.Json
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Newtonsoft.Json prior to version 13.0.1 is vulnerable to Insecure Defaults due to improper handling of expressions with high nesting level that lead to StackOverFlow exception or high CPU and RAM usage. Exploiting this vulnerability results in Denial Of Service (DoS). The serialization and deserialization path have different properties regarding the issue. Deserializing methods (like Serializing methods (like To mitigate the issue one either need to update Newtonsoft.Json to 13.0.1 or set
Repro code:
Additional affected product and version informationThe original statement about the problem only affecting IIS applications is misleading. Any application is affected, however the IIS has a behavior that stops restarting the instance after some time resulting in a harder-to-fix DoS.** Affected versions
10.0.1
10.0.1-beta1
10.0.2
10.0.3
11.0.1
11.0.1-beta1
11.0.1-beta2
11.0.1-beta3
11.0.2
12.0.1
12.0.1-beta1
12.0.1-beta2
+ 62 more Show less
12.0.2
12.0.2-beta1
12.0.2-beta2
12.0.2-beta3
12.0.3
12.0.3-beta1
12.0.3-beta2
13.0.1-beta1
13.0.1-beta2
3.5.8
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.5.1
4.5.10
4.5.11
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
6.0.1
6.0.1-beta1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.1
7.0.1-beta1
7.0.1-beta2
7.0.1-beta3
8.0.1
8.0.1-beta1
8.0.1-beta2
8.0.1-beta3
8.0.1-beta4
8.0.2
8.0.3
8.0.4-beta1
9.0.1
9.0.1-beta1
9.0.2-beta1
9.0.2-beta2
Fixed in
13.0.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
4.0.7
patch
|
|
4.0.6
patch
1 CVE
CVE-2024-21907
GHSA-5crp-9r3c-p9vr
Jun 22, 2022
Improper Handling of Exceptional Conditions in Newtonsoft.Json
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Newtonsoft.Json prior to version 13.0.1 is vulnerable to Insecure Defaults due to improper handling of expressions with high nesting level that lead to StackOverFlow exception or high CPU and RAM usage. Exploiting this vulnerability results in Denial Of Service (DoS). The serialization and deserialization path have different properties regarding the issue. Deserializing methods (like Serializing methods (like To mitigate the issue one either need to update Newtonsoft.Json to 13.0.1 or set
Repro code:
Additional affected product and version informationThe original statement about the problem only affecting IIS applications is misleading. Any application is affected, however the IIS has a behavior that stops restarting the instance after some time resulting in a harder-to-fix DoS.** Affected versions
10.0.1
10.0.1-beta1
10.0.2
10.0.3
11.0.1
11.0.1-beta1
11.0.1-beta2
11.0.1-beta3
11.0.2
12.0.1
12.0.1-beta1
12.0.1-beta2
+ 62 more Show less
12.0.2
12.0.2-beta1
12.0.2-beta2
12.0.2-beta3
12.0.3
12.0.3-beta1
12.0.3-beta2
13.0.1-beta1
13.0.1-beta2
3.5.8
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.5.1
4.5.10
4.5.11
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
6.0.1
6.0.1-beta1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.1
7.0.1-beta1
7.0.1-beta2
7.0.1-beta3
8.0.1
8.0.1-beta1
8.0.1-beta2
8.0.1-beta3
8.0.1-beta4
8.0.2
8.0.3
8.0.4-beta1
9.0.1
9.0.1-beta1
9.0.2-beta1
9.0.2-beta2
Fixed in
13.0.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
4.0.6
patch
|
|
4.0.5
patch
1 CVE
CVE-2024-21907
GHSA-5crp-9r3c-p9vr
Jun 22, 2022
Improper Handling of Exceptional Conditions in Newtonsoft.Json
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Newtonsoft.Json prior to version 13.0.1 is vulnerable to Insecure Defaults due to improper handling of expressions with high nesting level that lead to StackOverFlow exception or high CPU and RAM usage. Exploiting this vulnerability results in Denial Of Service (DoS). The serialization and deserialization path have different properties regarding the issue. Deserializing methods (like Serializing methods (like To mitigate the issue one either need to update Newtonsoft.Json to 13.0.1 or set
Repro code:
Additional affected product and version informationThe original statement about the problem only affecting IIS applications is misleading. Any application is affected, however the IIS has a behavior that stops restarting the instance after some time resulting in a harder-to-fix DoS.** Affected versions
10.0.1
10.0.1-beta1
10.0.2
10.0.3
11.0.1
11.0.1-beta1
11.0.1-beta2
11.0.1-beta3
11.0.2
12.0.1
12.0.1-beta1
12.0.1-beta2
+ 62 more Show less
12.0.2
12.0.2-beta1
12.0.2-beta2
12.0.2-beta3
12.0.3
12.0.3-beta1
12.0.3-beta2
13.0.1-beta1
13.0.1-beta2
3.5.8
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.5.1
4.5.10
4.5.11
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
6.0.1
6.0.1-beta1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.1
7.0.1-beta1
7.0.1-beta2
7.0.1-beta3
8.0.1
8.0.1-beta1
8.0.1-beta2
8.0.1-beta3
8.0.1-beta4
8.0.2
8.0.3
8.0.4-beta1
9.0.1
9.0.1-beta1
9.0.2-beta1
9.0.2-beta2
Fixed in
13.0.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
4.0.5
patch
|
|
4.0.4
patch
1 CVE
CVE-2024-21907
GHSA-5crp-9r3c-p9vr
Jun 22, 2022
Improper Handling of Exceptional Conditions in Newtonsoft.Json
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Newtonsoft.Json prior to version 13.0.1 is vulnerable to Insecure Defaults due to improper handling of expressions with high nesting level that lead to StackOverFlow exception or high CPU and RAM usage. Exploiting this vulnerability results in Denial Of Service (DoS). The serialization and deserialization path have different properties regarding the issue. Deserializing methods (like Serializing methods (like To mitigate the issue one either need to update Newtonsoft.Json to 13.0.1 or set
Repro code:
Additional affected product and version informationThe original statement about the problem only affecting IIS applications is misleading. Any application is affected, however the IIS has a behavior that stops restarting the instance after some time resulting in a harder-to-fix DoS.** Affected versions
10.0.1
10.0.1-beta1
10.0.2
10.0.3
11.0.1
11.0.1-beta1
11.0.1-beta2
11.0.1-beta3
11.0.2
12.0.1
12.0.1-beta1
12.0.1-beta2
+ 62 more Show less
12.0.2
12.0.2-beta1
12.0.2-beta2
12.0.2-beta3
12.0.3
12.0.3-beta1
12.0.3-beta2
13.0.1-beta1
13.0.1-beta2
3.5.8
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.5.1
4.5.10
4.5.11
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
6.0.1
6.0.1-beta1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.0.1
7.0.1-beta1
7.0.1-beta2
7.0.1-beta3
8.0.1
8.0.1-beta1
8.0.1-beta2
8.0.1-beta3
8.0.1-beta4
8.0.2
8.0.3
8.0.4-beta1
9.0.1
9.0.1-beta1
9.0.2-beta1
9.0.2-beta2
Fixed in
13.0.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
4.0.4
patch
|