github LuckyPennySoftware/AutoMapper v15.1.1

10 hours ago

What's Changed

  • docs: Document duplicate license message behavior and fixes by @Copilot in #4617

Security

Fixed an issue where certain cyclic or self-referential object graphs could trigger uncontrolled recursion during mapping, potentially resulting in stack exhaustion and denial of service.

Applications that process untrusted or attacker-controlled object graphs through affected mapping paths may be impacted.

Users should upgrade to this release.

Security advisory: GHSA-rvv3-g6hj-g44x

Thanks to @skdishansachin for responsibly disclosing this issue.

Full Changelog: v16.1.1...v15.1.1

Don't miss a new AutoMapper release

NewReleases is sending notifications on new releases.