Base solution for your next web application
Open Closed

ASP.NET Zero Core & jQuery Project – Unresolved High/Medium Security Issues and Outdated AutoMapper Dependency #12645


User avatar
0
[email protected] created

Dear ASP.NET Zero Support Team,

We have re-conducted a white-box security analysis using Checkmarx Enterprise Edition on the latest version (v15.2.0) of the ASP.NET Zero Core & jQuery project. The results indicate that there are still unresolved high- and medium-severity vulnerabilities originating from the framework itself. The report is available via the link: https://drive.google.com/drive/folders/1foBpeC7YCwnVQnYGSoYH03Vg__R4rREQ?usp=sharing Please download the report for review at your earliest convenience. (Note: The link will be removed after it has been accessed/downloaded due to internal security policies.)

Due to our company’s security policy, all systems must pass static code analysis with no high- or medium-risk findings before they can be deployed to production. Unfortunately, the current scan results do not meet this requirement.

Additionally, we have identified that the framework depends on ASP.NET Boilerplate (v14.0.0), which includes third-party packages with known high-severity vulnerabilities. In particular:

AutoMapper 14.0.0 is flagged with a high-severity vulnerability (CVE-2026-32933 / GHSA-rvv3-g6hj-g44x). Due to compatibility constraints, we are currently unable to upgrade AutoMapper to a secure version. Our company policy prohibits the use of third-party components with known security vulnerabilities.

Based on our analysis, a potential resolution would be:

Upgrading AutoMapper.Collection to ≥ 12.0.0 Upgrading AutoMapper to version 15.x Updating Abp.AutoMapper to support the newer versions

We would appreciate your assistance in confirming:

Whether there are plans to resolve the reported high and medium vulnerabilities in the framework. Whether the AutoMapper dependency will be updated in an upcoming release. If there are any recommended workarounds or patches to address these issues in the meantime.

Please let us know how these concerns can be resolved so that we can proceed with compliance and deployment.

Thank you for your support.

Markdown is supported
Copy & paste or drag & drop images (max 30 MB per image)

1 Answer(s)
  • User Avatar
    0
    oguzhanagir created
    Support Team

    Hi @itsdev2

    Thank you for sharing the detailed security report with us. We appreciate you taking the time to perform a thorough analysis and bringing these findings to our attention.

    We will review the reported high- and medium-severity vulnerabilities internally and plan the necessary fixes and improvements accordingly. Your report will be valuable in guiding this process.

    Regarding AutoMapper, ASP.NET Zero has already transitioned away from AutoMapper and now uses Mapperly as the default object mapping solution. This change was primarily driven by evolving licensing considerations around AutoMapper as well as performance and maintainability advantages offered by Mapperly.

    As a result, future improvements and updates will continue to align with this direction rather than upgrading AutoMapper dependencies. For projects still relying on AutoMapper, we recommend gradually migrating to Mapperly to remain aligned with the framework’s current architecture and avoid potential dependency-related risks.

    We will keep you informed once we have a clearer remediation plan for the reported vulnerabilities. In the meantime, if you have any additional findings or constraints to share, please feel free to do so.

    Best regards

    Markdown is supported
    Copy & paste or drag & drop images (max 30 MB per image)