๐Ÿ” CVE Alert

CVE-2026-32933

HIGH 7.5

AutoMapper Vulnerable to Denial of Service (DoS) via Uncontrolled Recursion

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
12th

AutoMapper is a convention-based object-object mapper in .NET. Versions prior to 15.1.1 and 16.1.1 are vulnerable to a Denial of Service (DoS) attack. When mapping deeply nested object graphs, the library uses recursive method calls without enforcing a default maximum depth limit. This allows an attacker to provide a specially crafted object graph that exhausts the thread's stack memory, triggering a `StackOverflowException` and causing the entire application process to terminate. Versions 15.1.1 and 16.1.1 fix the issue.

CWE CWE-674
Vendor luckypennysoftware
Product automapper
Published Mar 20, 2026
Last Updated Mar 20, 2026
Stay Ahead of the Next One

Get instant alerts for luckypennysoftware automapper

Be the first to know when new high vulnerabilities affecting luckypennysoftware automapper are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High

Affected Versions

LuckyPennySoftware / AutoMapper
>= 16.0.0, < 16.1.1 < 15.1.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/LuckyPennySoftware/AutoMapper/security/advisories/GHSA-rvv3-g6hj-g44x github.com: https://github.com/LuckyPennySoftware/AutoMapper/commit/0afaf1e91648fca1a57512e94dd00a76ee016816 github.com: https://github.com/LuckyPennySoftware/AutoMapper/releases/tag/v15.1.1 github.com: https://github.com/LuckyPennySoftware/AutoMapper/releases/tag/v16.1.1