{"api_version":"1","generated_at":"2026-07-23T22:00:46+00:00","cve":"CVE-2024-21909","urls":{"html":"https://cve.report/CVE-2024-21909","api":"https://cve.report/api/cve/CVE-2024-21909.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2024-21909","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2024-21909"},"summary":{"title":"Denial of service in CBOR library","description":"PeterO.Cbor versions 4.0.0 through 4.5.0 are vulnerable to a denial of \nservice vulnerability. An attacker may trigger the denial of service \ncondition by providing crafted data to the DecodeFromBytes or other \ndecoding mechanisms in PeterO.Cbor. Depending on the usage of the \nlibrary, an unauthenticated and remote attacker may be able to cause the\n denial of service condition.","state":"PUBLISHED","assigner":"VulnCheck","published_at":"2024-01-03 16:15:09","updated_at":"2026-07-14 23:17:14"},"problem_types":["CWE-407","CWE-407 CWE-407 Inefficient Algorithmic Complexity"],"metrics":[{"version":"3.1","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"}},{"version":"3.1","source":"ADP","type":"DECLARED","score":"7.5","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"}},{"version":"3.1","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","score":"7.5","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"}}],"references":[{"url":"https://github.com/peteroupc/CBOR/commit/b4117dbbb4cd5a4a963f9d0c9aa132f033e15b95","name":"https://github.com/peteroupc/CBOR/commit/b4117dbbb4cd5a4a963f9d0c9aa132f033e15b95","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"","mime":"","httpstatus":"200","archivestatus":"404"},{"url":"https://github.com/advisories/GHSA-6r92-cgxc-r5fg","name":"https://github.com/advisories/GHSA-6r92-cgxc-r5fg","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"","mime":"","httpstatus":"200","archivestatus":"404"},{"url":"https://github.com/peteroupc/CBOR/compare/v4.5...v4.5.1","name":"https://github.com/peteroupc/CBOR/compare/v4.5...v4.5.1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"],"title":"","mime":"","httpstatus":"200","archivestatus":"404"},{"url":"https://vulncheck.com/advisories/vc-advisory-GHSA-6r92-cgxc-r5fg","name":"https://vulncheck.com/advisories/vc-advisory-GHSA-6r92-cgxc-r5fg","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"","mime":"","httpstatus":"200","archivestatus":"404"},{"url":"https://github.com/peteroupc/CBOR/security/advisories/GHSA-6r92-cgxc-r5fg","name":"https://github.com/peteroupc/CBOR/security/advisories/GHSA-6r92-cgxc-r5fg","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"","mime":"","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2024-21909","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2024-21909","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2024","cve_id":"21909","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"peteroupc","cpe5":"cbor","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":".net","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2024","cve_id":"21909","cve":"CVE-2024-21909","epss":"0.010610000","percentile":"0.607650000","score_date":"2026-07-16","updated_at":"2026-07-17 00:05:21"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-01T22:35:34.565Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["vendor-advisory","x_transferred"],"url":"https://github.com/peteroupc/CBOR/security/advisories/GHSA-6r92-cgxc-r5fg"},{"tags":["patch","x_transferred"],"url":"https://github.com/peteroupc/CBOR/commit/b4117dbbb4cd5a4a963f9d0c9aa132f033e15b95"},{"tags":["related","x_transferred"],"url":"https://github.com/peteroupc/CBOR/compare/v4.5...v4.5.1"},{"tags":["third-party-advisory","x_transferred"],"url":"https://github.com/advisories/GHSA-6r92-cgxc-r5fg"},{"tags":["third-party-advisory","x_transferred"],"url":"https://vulncheck.com/advisories/vc-advisory-GHSA-6r92-cgxc-r5fg"}],"title":"CVE Program Container"},{"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"}},{"other":{"content":{"id":"CVE-2024-21909","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2025-05-09T23:31:17.137288Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2025-06-03T14:43:33.578Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"collectionURL":"https://nuget.org/packages","defaultStatus":"unaffected","packageName":"PeterO.Cbor","packageURL":"pkg:nuget/PeterO.Cbor","versions":[{"lessThan":"4.5.1","status":"affected","version":"4.0.0","versionType":"semver 2.0.0"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:a:peteroupc:cbor:*:*:*:*:*:.net:*:*","versionEndExcluding":"4.5.1","versionStartIncluding":"4.0.0","vulnerable":true}],"negate":false,"operator":"OR"}],"operator":"OR"}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"PeterO.Cbor versions 4.0.0 through 4.5.0 are vulnerable to a denial of \nservice vulnerability. An attacker may trigger the denial of service \ncondition by providing crafted data to the DecodeFromBytes or other \ndecoding mechanisms in PeterO.Cbor. Depending on the usage of the \nlibrary, an unauthenticated and remote attacker may be able to cause the\n denial of service condition.<br>"}],"value":"PeterO.Cbor versions 4.0.0 through 4.5.0 are vulnerable to a denial of \nservice vulnerability. An attacker may trigger the denial of service \ncondition by providing crafted data to the DecodeFromBytes or other \ndecoding mechanisms in PeterO.Cbor. Depending on the usage of the \nlibrary, an unauthenticated and remote attacker may be able to cause the\n denial of service condition."}],"problemTypes":[{"descriptions":[{"cweId":"CWE-407","description":"CWE-407 Inefficient Algorithmic Complexity","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-07-14T22:54:35.829Z","orgId":"83251b91-4cc7-4094-a5c7-464a1b83ea10","shortName":"VulnCheck"},"references":[{"tags":["vendor-advisory"],"url":"https://github.com/peteroupc/CBOR/security/advisories/GHSA-6r92-cgxc-r5fg"},{"tags":["patch"],"url":"https://github.com/peteroupc/CBOR/commit/b4117dbbb4cd5a4a963f9d0c9aa132f033e15b95"},{"tags":["related"],"url":"https://github.com/peteroupc/CBOR/compare/v4.5...v4.5.1"},{"tags":["vendor-advisory"],"url":"https://github.com/advisories/GHSA-6r92-cgxc-r5fg"},{"tags":["third-party-advisory"],"url":"https://vulncheck.com/advisories/vc-advisory-GHSA-6r92-cgxc-r5fg"}],"source":{"discovery":"INTERNAL"},"title":"Denial of service in CBOR library","x_generator":{"engine":"vulncheck"}}},"cveMetadata":{"assignerOrgId":"83251b91-4cc7-4094-a5c7-464a1b83ea10","assignerShortName":"VulnCheck","cveId":"CVE-2024-21909","datePublished":"2024-01-03T15:41:57.739Z","dateReserved":"2024-01-03T14:21:17.583Z","dateUpdated":"2026-07-14T22:54:35.829Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2024-01-03 16:15:09","lastModifiedDate":"2026-07-14 23:17:14","problem_types":["CWE-407","CWE-407 CWE-407 Inefficient Algorithmic Complexity"],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-05-09T23:31:17.137288Z","id":"CVE-2024-21909","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:peteroupc:cbor:*:*:*:*:*:.net:*:*","versionStartIncluding":"4.0.0","versionEndExcluding":"4.5.1","matchCriteriaId":"1ACE4764-C56D-427B-99DA-52922CA6C062"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2024","CveId":"21909","Ordinal":"1","Title":"Denial of service in CBOR library","CVE":"CVE-2024-21909","Year":"2024"},"notes":[{"CveYear":"2024","CveId":"21909","Ordinal":"1","NoteData":"PeterO.Cbor versions 4.0.0 through 4.5.0 are vulnerable to a denial of \nservice vulnerability. An attacker may trigger the denial of service \ncondition by providing crafted data to the DecodeFromBytes or other \ndecoding mechanisms in PeterO.Cbor. Depending on the usage of the \nlibrary, an unauthenticated and remote attacker may be able to cause the\n denial of service condition.","Type":"Description","Title":"Denial of service in CBOR library"}]}}}