AI agents: use the documentation index at llms.txt to locate machine-readable pages. This section is indexed by https://docs.particular.net/security-advisories/llms.txt. The markdown version of this page is served as plain text. An MCP server at /mcp serves the same content via the search_docs and read_doc tools; it is read-only and needs no credentials. Markdown versions of documentation pages are available by appending .md to the page URL. Directory URLs use index.md. They are served as text/plain because some retrieval backends reject text/markdown.

GHSA-q834-8qmm-v933

Security Advisory Id GHSA-q834-8qmm-v933

This advisory discloses a security vulnerability Patches for components to update their dependencies to avoid references that have the GHSA-q834-8qmm-v933 security advisory: OpenTelemetry dotnet: OTLP exporter reads unbounded HTTP response bodies.

Patch releases

ComponentVersionWhere to get it
ServiceControl6.14.2The downloads page
Particular.ServiceControl.Management6.14.2Update-Module -Name Particular.ServiceControl.Management -RequiredVersion 6.14.2
servicecontrol6.14.2Docker Hub or docker pull particular/servicecontrol:6.14.2
servicecontrol-audit6.14.2Docker Hub or docker pull particular/servicecontrol-audit:6.14.2
servicecontrol-monitoring6.14.2Docker Hub or docker pull particular/servicecontrol-monitoring:6.14.2
servicecontrol-ravendb6.14.2Docker Hub or docker pull particular/servicecontrol-ravendb:6.14.2

How to know if you are affected

You are affected if you are using previous versions of any of these components, but this doesn't necessarily mean you are vulnerable.

Symptoms

For NuGet packages your projects have the setting NuGetAuditMode set to all and see transitive dependency warnings at build time that mention Particular packages.

Other components of the platform will not have any symptoms.

When to upgrade

You should upgrade immediately if you are affected. Otherwise, you should upgrade during your next maintenance window.