Executive brief
Meridian, a data mapping and mediation library, contains multiple security flaws that could allow an attacker to crash an application or leak sensitive information. By sending specially crafted data, an attacker can bypass safety limits to exhaust system memory or cause a service outage. Additionally, some configurations may inadvertently expose internal technical details like stack traces to external monitoring systems.
Technical details
Meridian v2.1.0 contains nine security vulnerabilities across its Mapping and Mediator components. The most severe issues involve CWE-770 and CWE-674, where the 'IMapper.Map(source, destination)' overload and '.UseDestinationValue()' configurations bypass 'DefaultMaxCollectionItems' and 'DefaultMaxDepth' safety caps. This allows an unauthenticated attacker to provide large or self-referential collection payloads that cause heap exhaustion or stack overflow. Other issues include CWE-665 (constructor invariant bypass), CWE-532 (information disclosure of stack traces in OpenTelemetry), and CWE-400 (unbounded retry and fan-out amplification). All issues are addressed in version 2.1.1 by enforcing shared cap helpers, incrementing recursion depth correctly, and introducing default limits for retries and parallelism.
Affected products
- UmutKorkmaz Meridian.Mapping >= 2.0.0, < 2.1.1
- UmutKorkmaz Meridian.Mediator >= 2.0.0, < 2.1.1
Timeline
- 2026-04-16: disclosed
- 2026-04-16: patched
- 2026-04-16: advisory