CVE-2026-32933

AutoMapper is a convention-based object-object mapper in .NET. Versions prior to 15.1.1 and 16.1.1 are vulnerable to a Denial of Service (DoS) attack. When mapping deeply nested object graphs, the library uses recursive method calls without enforcing a default maximum depth limit. This allows an attacker to provide a specially crafted object graph that exhausts the thread's stack memory, triggering a `StackOverflowException` and causing the entire application process to terminate. Versions 15.1.1 and 16.1.1 fix the issue.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:luckypennysoftware:automapper:*:*:*:*:*:*:*:*
cpe:2.3:a:luckypennysoftware:automapper:*:*:*:*:*:*:*:*

History

08 Apr 2026, 20:52

Type Values Removed Values Added
Summary
  • (es) AutoMapper es un mapeador de objetos a objetos basado en convenciones en .NET. Las versiones anteriores a la 15.1.1 y 16.1.1 son vulnerables a un ataque de denegación de servicio (DoS). Al mapear grafos de objetos profundamente anidados, la biblioteca utiliza llamadas a métodos recursivas sin imponer un límite de profundidad máxima predeterminado. Esto permite a un atacante proporcionar un grafo de objetos especialmente diseñado que agota la memoria de pila del hilo, lo que desencadena una 'StackOverflowException' y provoca la terminación de todo el proceso de la aplicación. Las versiones 15.1.1 y 16.1.1 solucionan el problema.
First Time Luckypennysoftware
Luckypennysoftware automapper
CPE cpe:2.3:a:luckypennysoftware:automapper:*:*:*:*:*:*:*:*
References () https://github.com/LuckyPennySoftware/AutoMapper/commit/0afaf1e91648fca1a57512e94dd00a76ee016816 - () https://github.com/LuckyPennySoftware/AutoMapper/commit/0afaf1e91648fca1a57512e94dd00a76ee016816 - Patch
References () https://github.com/LuckyPennySoftware/AutoMapper/releases/tag/v15.1.1 - () https://github.com/LuckyPennySoftware/AutoMapper/releases/tag/v15.1.1 - Release Notes
References () https://github.com/LuckyPennySoftware/AutoMapper/releases/tag/v16.1.1 - () https://github.com/LuckyPennySoftware/AutoMapper/releases/tag/v16.1.1 - Release Notes
References () https://github.com/LuckyPennySoftware/AutoMapper/security/advisories/GHSA-rvv3-g6hj-g44x - () https://github.com/LuckyPennySoftware/AutoMapper/security/advisories/GHSA-rvv3-g6hj-g44x - Vendor Advisory, Exploit

20 Mar 2026, 03:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-20 03:16

Updated : 2026-04-08 20:52


NVD link : CVE-2026-32933

Mitre link : CVE-2026-32933

CVE.ORG link : CVE-2026-32933


JSON object : View

Products Affected

luckypennysoftware

  • automapper
CWE
CWE-674

Uncontrolled Recursion