This is a CodeQL issue. CodeQL tracking item can be found here.
More information on how to fix the issue here.
We can't simply use TypeNameHandling.None because that would be a breaking change, preventing exceptions from being deserialized. However, there are other workarounds that can be considered, as noted in the above informational link.