« Volver al listado

CVE-2026-32933

Estado: AnalizadaAlta (7.5)—

AutoMapper is a convention-based object-object mapper in .NET. Versions prior to 15.1.1 and 16.1.1 are vulnerable to a Denial of Service (DoS) attack. When mapping deeply nested object graphs, the library uses recursive method calls without enforcing a default maximum depth limit. This allows an attacker to provide a specially crafted object graph that exhausts the thread's stack memory, triggering a `StackOverflowException` and causing the entire application process to terminate. Versions 15.1.1 and 16.1.1 fix the issue.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vector CVSS AV:N/AC:L/PR:N permite acceso remoto sin autenticación. La descripción explícita de StackOverflowException causando terminación de proceso sustenta DoS (T1499.004: exhaustión de recursos de aplicación).

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-32933",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-32933",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-03-20T20:02:49.448369Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "LuckyPennySoftware",
          "product": "AutoMapper",
          "versions": [
            {
              "status": "affected",
              "version": ">= 16.0.0, < 16.1.1"
            },
            {
              "status": "affected",
              "version": "< 15.1.1"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-03-20T03:16:00.430",
  "references": [
    {
      "url": "https://github.com/LuckyPennySoftware/AutoMapper/commit/0afaf1e91648fca1a57512e94dd00a76ee016816",
      "tags": [
        "Patch"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/LuckyPennySoftware/AutoMapper/releases/tag/v15.1.1",
      "tags": [
        "Release Notes"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/LuckyPennySoftware/AutoMapper/releases/tag/v16.1.1",
      "tags": [
        "Release Notes"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/LuckyPennySoftware/AutoMapper/security/advisories/GHSA-rvv3-g6hj-g44x",
      "tags": [
        "Exploit",
        "Vendor Advisory"
      ],
      "source": "security-advisories@github.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-674"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "AutoMapper is a convention-based object-object mapper in .NET. Versions prior to 15.1.1 and 16.1.1 are vulnerable to a Denial of Service (DoS) attack. When mapping deeply nested object graphs, the library uses recursive method calls without enforcing a default maximum depth limit. This allows an attacker to provide a specially crafted object graph that exhausts the thread's stack memory, triggering a `StackOverflowException` and causing the entire application process to terminate. Versions 15.1.1 and 16.1.1 fix the issue."
    },
    {
      "lang": "es",
      "value": "AutoMapper es un mapeador de objetos a objetos basado en convenciones en .NET. Las versiones anteriores a la 15.1.1 y 16.1.1 son vulnerables a un ataque de denegación de servicio (DoS). Al mapear grafos de objetos profundamente anidados, la biblioteca utiliza llamadas a métodos recursivas sin imponer un límite de profundidad máxima predeterminado. Esto permite a un atacante proporcionar un grafo de objetos especialmente diseñado que agota la memoria de pila del hilo, lo que desencadena una 'StackOverflowException' y provoca la terminación de todo el proceso de la aplicación. Las versiones 15.1.1 y 16.1.1 solucionan el problema."
    }
  ],
  "lastModified": "2026-06-17T10:36:35.263",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:luckypennysoftware:automapper:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ED1E9072-4965-4A55-9B9F-19C83A9ABD91",
              "versionEndExcluding": "15.1.1"
            },
            {
              "criteria": "cpe:2.3:a:luckypennysoftware:automapper:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "92FB97AB-2B2B-4D96-89D9-CE73ACABC164",
              "versionEndExcluding": "16.1.1",
              "versionStartIncluding": "16.0.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security-advisories@github.com"
}