GHSA-rvv3-g6hj-g44x

Suggest an improvement
Source
https://github.com/advisories/GHSA-rvv3-g6hj-g44x
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-rvv3-g6hj-g44x/GHSA-rvv3-g6hj-g44x.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-rvv3-g6hj-g44x
Aliases
Downstream
CGA (2)
ECHO (1)
Published
2026-03-13T20:57:07Z
Modified
2026-09-10T03:50:41Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
AutoMapper Vulnerable to Denial of Service (DoS) via Uncontrolled Recursion
Details

Summary

AutoMapper is vulnerable to a Denial of Service (DoS) attack. When mapping deeply nested object graphs, the library uses recursive method calls without enforcing a default maximum depth limit. This allows an attacker to provide a specially crafted object graph that exhausts the thread's stack memory, triggering a StackOverflowException and causing the entire application process to terminate.

Description

The vulnerability exists in the core mapping engine. When a source object contains a property of the same type (or a type that eventually points back to itself), AutoMapper recursively attempts to map each level.

Because there is no default limit on how many levels deep this recursion can go, a sufficiently nested object (approximately 25,000+ levels in standard .NET environments) will exceed the stack size. Since StackOverflowException cannot be caught in modern .NET runtimes, the application cannot recover and will crash immediately.

Impact

  • Availability: An attacker can crash the application server, leading to a complete Denial of Service.
  • Process Termination: Unlike standard exceptions, this terminates the entire process, not just the individual request thread.

Proof of Concept (PoC)

The following C# code demonstrates the crash by creating a nested "Circular" object graph and attempting to map it:

class Circular { public Circular Self { get; set; } }

// Setup configuration
var config = new MapperConfiguration(cfg => {
    cfg.CreateMap<Circular, Circular>();
});
var mapper = config.CreateMapper();

// Create a deeply nested object (28,000+ levels)
var root = new Circular();
var current = root;
for (int i = 0; i < 30000; i++) {
    current.Self = new Circular();
    current = current.Self;
}

// This call triggers the StackOverflowException and crashes the process
mapper.Map<Circular>(root);

Recommended Mitigation

  1. Secure Defaults: Implement a default MaxDepth (e.g., 32 or 64) for all mapping operations.
  2. Configurable Limit: Allow users to increase this limit if necessary, but ensure it is enabled by default to protect unsuspecting developers.
Database specific
{
    "cwe_ids":  [
        "CWE-674"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-03-13T20:57:07Z",
    "nvd_published_at":  "2026-03-20T03:16:00Z",
    "severity":  "HIGH"
}
References

Affected packages

NuGet / AutoMapper

Package

Name
AutoMapper
View open source insights on deps.dev
Purl
pkg:nuget/AutoMapper

Affected ranges

Type
ECOSYSTEM
Events
Introduced
16.0.0
Fixed
16.1.1

Affected versions

16.*
16.0.0
16.1.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-rvv3-g6hj-g44x/GHSA-rvv3-g6hj-g44x.json"

NuGet / AutoMapper

Package

Name
AutoMapper
View open source insights on deps.dev
Purl
pkg:nuget/AutoMapper

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
15.1.1

Affected versions

1.*
1.1.0.118
1.1.1
1.1.2
2.*
2.0.0
2.1.1
2.1.262
2.1.265
2.1.266
2.1.267
2.2.0
2.2.1-ci10
2.2.1-ci1000
2.2.1-ci11
2.2.1-ci15
2.2.1-ci16
2.2.1-ci17
2.2.1-ci4
2.2.1-ci5
2.2.1-ci6
2.2.1-ci7
2.2.1-ci8
2.2.1-ci9
2.2.1-ci9000
2.2.1-ci9001
2.2.1-ci9002
2.2.1-ci9003
2.2.1-ci9004
2.2.1-ci9005
2.2.1-ci9006
2.2.1
2.2.24-ci
2.2.25-ci
3.*
3.0.0-ci1026
3.0.0-ci1028
3.0.0-ci1029
3.0.0-ci1031
3.0.0-ci1032
3.0.0-ci1033
3.0.0-ci1034
3.0.0-ci1035
3.0.0-ci1036
3.0.0-ci1037
3.0.0-ci1038
3.0.0-ci1039
3.0.0-ci1040
3.0.0-ci1041
3.0.0-ci1042
3.0.0-ci1043
3.0.0-ci1053
3.0.0
3.1.0-ci1014
3.1.0-ci1016
3.1.0-ci1017
3.1.0-ci1018
3.1.0-ci1019
3.1.0-ci1020
3.1.0-ci1021
3.1.0-ci1022
3.1.0-ci1023
3.1.0-ci1024
3.1.0-ci1026
3.1.0-ci1027
3.1.0-ci1032
3.1.0-ci1033
3.1.0-ci1034
3.1.0-ci1035
3.1.0-ci1036
3.1.0-ci1037
3.1.0-ci1038
3.1.0-ci1043
3.1.0-ci1044
3.1.0-ci1045
3.1.0-ci1046
3.1.0-ci1047
3.1.0-ci1048
3.1.0-ci1049
3.1.0-ci1050
3.1.0-ci1051
3.1.0-ci1053
3.1.0-ci1056
3.1.0-ci1058
3.1.0
3.1.1-ci1000
3.1.1-ci1003
3.1.1
3.2.0-ci1000
3.2.0-ci1001
3.2.0-ci1002
3.2.0-ci1003
3.2.0-ci1004
3.2.0-ci1005
3.2.0-ci1008
3.2.0-ci1009
3.2.0-ci1010
3.2.0-ci1011
3.2.0-ci1014
3.2.0-ci1015
3.2.0-ci1016
3.2.0-ci1017
3.2.0-ci1021
3.2.0-ci1022
3.2.0-ci1023
3.2.0-ci1024
3.2.0-ci1025
3.2.0-ci1026
3.2.0-ci1027
3.2.0-ci1028
3.2.0-ci1029
3.2.0-ci1030
3.2.0-ci1033
3.2.0-ci1034
3.2.0-ci1035
3.2.0-ci1036
3.2.0-ci1037
3.2.0-ci1038
3.2.0-ci1039
3.2.0-ci1040
3.2.0-ci1041
3.2.0-ci1042
3.2.0-ci1043
3.2.0
3.2.1-ci1000
3.2.1-ci1001
3.2.1-ci1002
3.2.1
3.3.0-ci1000
3.3.0-ci1001
3.3.0-ci1002
3.3.0-ci1003
3.3.0-ci1004
3.3.0-ci1005
3.3.0-ci1006
3.3.0-ci1007
3.3.0-ci1008
3.3.0-ci1009
3.3.0-ci1016
3.3.0-ci1017
3.3.0-ci1018
3.3.0-ci1019
3.3.0-ci1020
3.3.0-ci1021
3.3.0-ci1022
3.3.0-ci1023
3.3.0-ci1024
3.3.0-ci1025
3.3.0-ci1026
3.3.0-ci1027
3.3.0-ci1028
3.3.0-ci1029
3.3.0-ci1030
3.3.0-ci1031
3.3.0-ci1032
3.3.0-ci1033
3.3.0
3.3.1
4.*
4.0.0-alpha1
4.0.0-ci1002
4.0.0-ci1004
4.0.0-ci1006
4.0.0-ci1007
4.0.0-ci1014
4.0.0-ci1015
4.0.0-ci1017
4.0.0-ci1018
4.0.0-ci1019
4.0.0-ci1020
4.0.0-ci1021
4.0.0-ci1026
4.0.0-ci1031
4.0.0-ci1032
4.0.0-ci1034
4.0.0-ci1036
4.0.0-ci1038
4.0.0-ci1046
4.0.0-ci1049
4.0.0-ci1050
4.0.0-ci1051
4.0.0-ci1052
4.0.0-ci1053
4.0.0-ci1054
4.0.0-ci1056
4.0.0-ci1057
4.0.0-ci1061
4.0.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1.0
4.1.1
4.2.0
4.2.1
5.*
5.0.0-beta-1
5.0.0
5.0.1
5.0.2
5.1.0
5.1.1
5.2.0
6.*
6.0.0
6.0.1
6.0.2
6.1.0
6.1.1
6.2.0
6.2.1
6.2.2
7.*
7.0.0-alpha-0001
7.0.0
7.0.1
8.*
8.0.0
8.1.0
8.1.1
9.*
9.0.0
10.*
10.0.0
10.1.0
10.1.1
11.*
11.0.0
11.0.1
12.*
12.0.0
12.0.1
13.*
13.0.0
13.0.1
14.*
14.0.0
15.*
15.0.0
15.0.1
15.1.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-rvv3-g6hj-g44x/GHSA-rvv3-g6hj-g44x.json"