CVE-2026-32933 PUBLISHED

AutoMapper Vulnerable to Denial of Service (DoS) via Uncontrolled Recursion

Assigner: GitHub_M
Reserved: 17.03.2026 Published: 20.03.2026 Updated: 20.03.2026

AutoMapper is a convention-based object-object mapper in .NET. Versions prior to 15.1.1 and 16.1.1 are vulnerable to a Denial of Service (DoS) attack. When mapping deeply nested object graphs, the library uses recursive method calls without enforcing a default maximum depth limit. This allows an attacker to provide a specially crafted object graph that exhausts the thread's stack memory, triggering a StackOverflowException and causing the entire application process to terminate. Versions 15.1.1 and 16.1.1 fix the issue.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS Score: 7.5

Product Status

Vendor LuckyPennySoftware
Product AutoMapper
Versions
  • Version >= 16.0.0, < 16.1.1 is affected
  • Version < 15.1.1 is affected

References

Problem Types

  • CWE-674: Uncontrolled Recursion CWE