github LuckyPennySoftware/AutoMapper v16.1.1

6 hours ago

What's Changed

Security

Fixed an issue where certain cyclic or self-referential object graphs could trigger uncontrolled recursion during mapping, potentially resulting in stack exhaustion and denial of service.

Applications that process untrusted or attacker-controlled object graphs through affected mapping paths may be impacted.

Users should upgrade to this release.

Security advisory: GHSA-rvv3-g6hj-g44x

Thanks to @bluefossa for responsibly disclosing this issue.

Full Changelog: v16.1.0...v16.1.1

Don't miss a new AutoMapper release

NewReleases is sending notifications on new releases.