CVE-2026-32933
HIGHAutoMapper Vulnerable to Denial of Service (DoS) via Uncontrolled Recursion
Title source: cnaDescription
AutoMapper is a convention-based object-object mapper in .NET. Versions prior to 15.1.1 and 16.1.1 are vulnerable to a Denial of Service (DoS) attack. When mapping deeply nested object graphs, the library uses recursive method calls without enforcing a default maximum depth limit. This allows an attacker to provide a specially crafted object graph that exhausts the thread's stack memory, triggering a `StackOverflowException` and causing the entire application process to terminate. Versions 15.1.1 and 16.1.1 fix the issue.
Scores
CVSS v3
7.5
EPSS
0.0002
EPSS Percentile
5.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-674
Status
published
Products (4)
luckypennysoftware/automapper
< 15.1.1
LuckyPennySoftware/AutoMapper
< 15.1.1
LuckyPennySoftware/AutoMapper
>= 16.0.0, < 16.1.1
nuget/AutoMapper
16.0.0 - 16.1.1NuGet
Published
Mar 20, 2026
Tracked Since
Mar 20, 2026