# Newtonsoft Serializer Upgrade Version 2 to 3 ## NewtonsoftSerializer obsolete The `NewtonsoftSerializer` is obsolete in NServiceBus version 8. It uses `TypeNameHandling.Auto` as its default value which can be a security risk as it allows the message payload to control the deserialization target type. See [CA2326: Do not use TypeNameHandling values other than None](https://learn.microsoft.com/en-us/dotnet/fundamentals/code-analysis/quality-rules/ca2326) for further details on this vulnerability. A new serializer `NewtonsoftJsonSerializer` has been introduced which uses `TypeNameHandling.None` as its default value. Instead of: ```csharp var serialization = endpointConfiguration.UseSerialization(); ``` Use: ```csharp var serialization = endpointConfiguration.UseSerialization(); ``` If `TypeNameHandling.Auto` is required, customize the instance of [JsonSerializerSettings](https://www.newtonsoft.com/json/help/html/T_Newtonsoft_Json_JsonSerializerSettings.htm) used for serialization. See [the Json.Net Serializer documentation](/nservicebus/serialization/newtonsoft.md) for more information.