Released DotVVM 2.3.3 with an important bug fix

Published: 11/4/2019 4:54:23 PM

We have just released DotVVM 2.3.3 which fixes a significant bug in DotVVM error page.


The bug happened only:

  • when the application was using Newtonsoft.Json 11.0.2 or higher
  • in the debug mode where the error page is enabled
  • when there is a syntax error in a DotVVM page

The issue is caused by serialization of an exception thrown by DotVVM (we were using the information in the error page) and can cause StackOverflowException or infinite loop in the worker thread of the application.

All the behavior mentioned above can occur only in case of a syntax error in a DotVVM page, however there might be some users who deployed a debug version of an application which includes some page with syntax errors, and since the bug can cause an infinite loop, it may be a simple way for a DOS attack.

Our tests didn’t catch this issue as we were using older version of Newtonsoft.Json where everything worked normally.


We strongly recommend everyone to update to DotVVM 2.3.3 as soon as possible and to make sure that you are not deploying the debug version with error page turned on.

The new version can also greatly improve the dev experience as some errors might not been displayed correctly in the error page in some cases.

Tomáš Herceg

I am the CEO of RIGANTI, a small software development company located in Prague, Czech Republic.

I am Microsoft Most Valuable Professional and the founder of DotVVM project.

Subscribe to the newsletter!

Thank you for subscribing!

Social Sites