StackRadar

CVE-2026-32933

High

Advisory

Published 13 Mar 2026In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.005
44th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
10
of 17,781 indexed, latest versions
Container images
26
deployed by those charts
Fix available
1 of 1
affected package

AutoMapper Vulnerable to Denial of Service (DoS) via Uncontrolled Recursion

Carried by container images the latest versions of 10 of 17,781 indexed charts deploy, on 26 images.

Affected packageAffected versionsFixed inImages
AutoMappernuget6.1.1, 9.0.0, 10.1.1, 11.0.1+1 more15.1.126
OSV records
GHSA-rvv3-g6hj-g44x

Charts affected

10 by stars
ChartLatestAffected imagesRadar Score
eshoponabpabp-charts1.0.08 of 15See more

eshoponabp abp-charts 1.0.0

8 of the 15 container images this version deploys carry CVE-2026-32933.

Container imageDigestPackageFixed in
ghcr.io/volosoft/eshoponabp/app-authserver:1.0.022ce496c67d7
AutoMapper@10.1.1
15.1.1
ghcr.io/volosoft/eshoponabp/app-publicweb:1.0.07e53010dda55
AutoMapper@10.1.1
15.1.1
ghcr.io/volosoft/eshoponabp/service-administration:1.0.0206a9bee17a8
AutoMapper@10.1.1
15.1.1
ghcr.io/volosoft/eshoponabp/service-basket:1.0.0dd5ce454072e
AutoMapper@10.1.1
15.1.1
ghcr.io/volosoft/eshoponabp/service-catalog:1.0.07ecb00f53d99
AutoMapper@10.1.1
15.1.1
ghcr.io/volosoft/eshoponabp/service-identity:1.0.0e53bf47b62d0
AutoMapper@10.1.1
15.1.1
ghcr.io/volosoft/eshoponabp/service-ordering:1.0.15e836b17337f
AutoMapper@10.1.1
15.1.1
ghcr.io/volosoft/eshoponabp/service-payment:1.0.02ca91145099c
AutoMapper@10.1.1
15.1.1

Open the chart page →

19,799
voice-biometricslumenvox2.0.19 of 26See more

voice-biometrics lumenvox 2.0.1

9 of the 26 container images this version deploys carry CVE-2026-32933.

Container imageDigestPackageFixed in
lumenvox/cloud-assure-api:2.0.0fcb9fb54a9fd
AutoMapper@10.1.1
15.1.1
lumenvox/cloud-assure-identity:2.0.0147854a3c916
AutoMapper@10.1.1
15.1.1
lumenvox/cloud-audit:2.0.079428add7f38
AutoMapper@10.1.1
15.1.1
lumenvox/cloud-configuration:2.0.017fbce1a8bc6
AutoMapper@10.1.1
15.1.1
lumenvox/cloud-engine-resource:2.0.0e2e5abe27abc
AutoMapper@10.1.1
15.1.1
lumenvox/cloud-management-api:2.0.0b9a23345eabd
AutoMapper@10.1.1
15.1.1
lumenvox/cloud-reporting-api:2.0.0dbbaf5462ad6
AutoMapper@10.1.1
15.1.1
lumenvox/cloud-transaction:2.0.08b74f9d3ba09
AutoMapper@10.1.1
15.1.1
lumenvox/cloud-voice-verifier:2.0.014170ad34903
AutoMapper@10.1.1
15.1.1

Open the chart page →

70,741
testhubteshubVerified publisher0.1.41 of 3See more

testhub teshub 0.1.4

1 of the 3 container images this version deploys carry CVE-2026-32933.

Container imageDigestPackageFixed in
testhubio/testhub-api:on-prem56badee134b9
AutoMapper@9.0.0
15.1.1

Open the chart page →

7,517
ombibryanalves0.4.01 of 1See more

ombi bryanalves 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-32933.

Container imageDigestPackageFixed in
linuxserver/ombi:3.0.4572-ls452fbb21fb4903
AutoMapper@6.1.1
15.1.1

Open the chart page →

10,776
ConvertServiceWeb-Helm-Buildconvertserviceweb-helm-build0.1.12 of 7See more

ConvertServiceWeb-Helm-Build convertserviceweb-helm-build 0.1.1

2 of the 7 container images this version deploys carry CVE-2026-32933.

Container imageDigestPackageFixed in
aidasi/swpapi:v1-1-net6-k8s-test-beta838b5e2080bc
AutoMapper@11.0.1
15.1.1
aidasi/swpidentity:v1-1-net6-k8s-test-betad433285c7d5a
AutoMapper@10.1.1
15.1.1

Open the chart page →

10,091
nethermindethersphereVerified publisher0.2.11 of 1See more

nethermind ethersphere 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-32933.

Container imageDigestPackageFixed in
nethermind/nethermind:1.14.615517708c3b6
AutoMapper@9.0.0
15.1.1

Open the chart page →

4,920
faasnetfaasnet0.0.41 of 5See more

faasnet faasnet 0.0.4

1 of the 5 container images this version deploys carry CVE-2026-32933.

Container imageDigestPackageFixed in
simpleidserver/faaskubernetes:0.0.49007e742dd48
AutoMapper@9.0.0
15.1.1

Open the chart page →

7,617
jackettgeek-cookbookVerified publisher11.7.21 of 1See more

jackett geek-cookbook 11.7.2

1 of the 1 container images this version deploys carry CVE-2026-32933.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/jackett:v0.20.13163a4715b46aa2
AutoMapper@10.1.1
15.1.1

Open the chart page →

9,698
innago-vault-k8s-role-operatorinnagoVerified publisher2.0.51 of 1See more

innago-vault-k8s-role-operator innago 2.0.5

1 of the 1 container images this version deploys carry CVE-2026-32933.

Container imageDigestPackageFixed in
ghcr.io/innago-property-management/innago-vault-k8s-role-operator:2.0.0ed1c3fd04057
AutoMapper@12.0.0
15.1.1

Open the chart page →

1,052
jackettlib42Verified publisher1.1.01 of 1See more

jackett lib42 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-32933.

Container imageDigestPackageFixed in
lib42/jackett:latesta55596cda383
AutoMapper@10.1.1
15.1.1

Open the chart page →

4,620

Container images carrying it

26 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
aidasi/swpapi:v1-1-net6-k8s-test-beta838b5e2080bc
AutoMapper@11.0.1
15.1.1
1
aidasi/swpidentity:v1-1-net6-k8s-test-betad433285c7d5a
AutoMapper@10.1.1
15.1.1
1
lib42/jackett:latesta55596cda383
AutoMapper@10.1.1
15.1.1
1
linuxserver/ombi:3.0.4572-ls452fbb21fb4903
AutoMapper@6.1.1
15.1.1
1
lumenvox/cloud-assure-api:2.0.0fcb9fb54a9fd
AutoMapper@10.1.1
15.1.1
1
lumenvox/cloud-assure-identity:2.0.0147854a3c916
AutoMapper@10.1.1
15.1.1
1
lumenvox/cloud-audit:2.0.079428add7f38
AutoMapper@10.1.1
15.1.1
1
lumenvox/cloud-configuration:2.0.017fbce1a8bc6
AutoMapper@10.1.1
15.1.1
1
lumenvox/cloud-engine-resource:2.0.0e2e5abe27abc
AutoMapper@10.1.1
15.1.1
1
lumenvox/cloud-management-api:2.0.0b9a23345eabd
AutoMapper@10.1.1
15.1.1
1
lumenvox/cloud-reporting-api:2.0.0dbbaf5462ad6
AutoMapper@10.1.1
15.1.1
1
lumenvox/cloud-transaction:2.0.08b74f9d3ba09
AutoMapper@10.1.1
15.1.1
1
lumenvox/cloud-voice-verifier:2.0.014170ad34903
AutoMapper@10.1.1
15.1.1
1
nethermind/nethermind:1.14.615517708c3b6
AutoMapper@9.0.0
15.1.1
1
simpleidserver/faaskubernetes:0.0.49007e742dd48
AutoMapper@9.0.0
15.1.1
1
testhubio/testhub-api:on-prem56badee134b9
AutoMapper@9.0.0
15.1.1
1
ghcr.io/innago-property-management/innago-vault-k8s-role-operator:2.0.0ed1c3fd04057
AutoMapper@12.0.0
15.1.1
1
ghcr.io/k8s-at-home/jackett:v0.20.13163a4715b46aa2
AutoMapper@10.1.1
15.1.1
1
ghcr.io/volosoft/eshoponabp/app-authserver:1.0.022ce496c67d7
AutoMapper@10.1.1
15.1.1
1
ghcr.io/volosoft/eshoponabp/app-publicweb:1.0.07e53010dda55
AutoMapper@10.1.1
15.1.1
1
ghcr.io/volosoft/eshoponabp/service-administration:1.0.0206a9bee17a8
AutoMapper@10.1.1
15.1.1
1
ghcr.io/volosoft/eshoponabp/service-basket:1.0.0dd5ce454072e
AutoMapper@10.1.1
15.1.1
1
ghcr.io/volosoft/eshoponabp/service-catalog:1.0.07ecb00f53d99
AutoMapper@10.1.1
15.1.1
1
ghcr.io/volosoft/eshoponabp/service-identity:1.0.0e53bf47b62d0
AutoMapper@10.1.1
15.1.1
1
ghcr.io/volosoft/eshoponabp/service-ordering:1.0.15e836b17337f
AutoMapper@10.1.1
15.1.1
1
ghcr.io/volosoft/eshoponabp/service-payment:1.0.02ca91145099c
AutoMapper@10.1.1
15.1.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.