Activities of "maziz101"

Detected security warning in Scriban (transitive dep of Volo.Abp.Emailing). Infinite recursion on circular refs causes StackOverflow/DoS crash during object rendering in templates (e.g., Layout.tpl). ​ Risky for email services with user-influenced data. Request:

  • Upgrade path/timeline for Scriban in next ABP release.
  • Config guidance for safe ObjectRecursionLimit.
  • Affected versions list.

Links:

  1. GitHub Advisory: https://github.com/scriban/scriban/security/advisories/GHSA-grr9-747v-xvcp
  2. OSV: https://github.com/ossf/osv.dev/blob/main/data/github/scriban/scriban/GHSA-grr9-747v-xvcp.json
  3. ​Patch Commit: https://github.com/scriban/scriban/commit/a6fe6074199e5c04f4d29dc8d8e652b24d33e3e4

Prioritize for production security.

We are using ABP Commercial and have AutoMapper version 14.x installed, which was recently flagged with a critical security vulnerability allowing Denial of Service (DoS) attacks through uncontrolled recursion on deeply nested object graphs of the same type. This triggers a StackOverflowException after ~25,000-30,000 levels, crashing the entire application process (unrecoverable in .NET). The issue affects all free versions prior to 15.1.1 and 16.1.1, which require a paid commercial license. As ABP.commercial users, we need guidance on: Official patch or upgrade timeline to a safe AutoMapper version (or integration with alternatives like Mapperly/Mapster). Temporary mitigation (e.g., global MaxDepth configuration in ABP's AutoMapper setup). Confirmation of affected ABP modules/services using AutoMapper.

Vulnerability Links:

  1. GitHub Security Advisory: https://github.com/LuckyPennySoftware/AutoMapper/security/advisories/GHSA-rvv3-g6hj-g44x
  2. NVD CVE Detail: https://nvd.nist.gov/vuln/detail/CVE-2026-32933
  3. OSV.dev: https://github.com/ossf/osv.dev/blob/main/data/github/LuckyPennySoftware/AutoMapper/GHSA-rvv3-g6hj-g44x.json (includes PoC) ​

Please prioritize as this exposes production apps to remote crashes via crafted API inputs. Thanks!

Showing 1 to 2 of 2 entries
Boost Your Development
ABP Live Training
Packages
See Trainings
Mastering ABP Framework Book
The Official Guide
Mastering
ABP Framework
Learn More
Mastering ABP Framework Book
Made with ❤️ on ABP v10.3.0-preview. Updated on March 13, 2026, 12:51
1
ABP Assistant
🔐 You need to be logged in to use the chatbot. Please log in first.