Skip to content

v16.1.1

Latest

Choose a tag to compare

@jbogard jbogard released this 13 Mar 15:27
· 3 commits to main since this release
7aea808

What's Changed

Security

Fixed an issue where certain cyclic or self-referential object graphs could trigger uncontrolled recursion during mapping, potentially resulting in stack exhaustion and denial of service.

Applications that process untrusted or attacker-controlled object graphs through affected mapping paths may be impacted.

Users should upgrade to this release.

Security advisory: GHSA-rvv3-g6hj-g44x

Thanks to @skdishansachin for responsibly disclosing this issue.

Full Changelog: v16.1.0...v16.1.1