Getting Started
Architecture
NServiceBus
Transports
Persistence
Hosting
ServiceInsight
ServicePulse
ServiceControl
Monitoring
Modernization
Samples

GHSA-pggp-6c3x-2xmx

Security Advisory Id GHSA-pggp-6c3x-2xmx

This advisory discloses a security vulnerability Patches for components to update their dependencies to avoid references that have the GHSA-pggp-6c3x-2xmx security advisory: Snappier has an infinite loop during SnappyStream decompression with malformed framed input.

Patch releases

ComponentVersionWhere to get it
NServiceBus.Storage.MongoDB3.0.7NuGet
NServiceBus.Storage.MongoDB.TransactionalSession3.0.7NuGet
NServiceBus.Storage.MongoDB4.2.2NuGet
NServiceBus.Storage.MongoDB.TransactionalSession4.2.2NuGet
NServiceBus.Storage.MongoDB5.0.2NuGet
NServiceBus.Storage.MongoDB.TransactionalSession5.0.2NuGet
NServiceBus.Storage.MongoDB6.0.3NuGet
NServiceBus.Storage.MongoDB.TransactionalSession6.0.3NuGet
NServiceBus.Storage.MongoDB7.0.2NuGet
NServiceBus.Storage.MongoDB.TransactionalSession7.0.2NuGet

How to know if you are affected

You are affected if you are using previous versions of any of these components, but this doesn't necessarily mean you are vulnerable.

Symptoms

For NuGet packages your projects have the setting NuGetAuditMode set to all and see transitive dependency warnings at build time that mention Particular packages.

Other components of the platform will not have any symptoms.

When to upgrade

You should upgrade immediately if you are affected. Otherwise, you should upgrade during your next maintenance window.