Security Advisory ID (GHSA-cvvh-rhrc-wg4q) - Patch releases available

Hi everyone,

We’ve just released patches for some of our components to update their dependencies to avoid references that have the GHSA-cvvh-rhrc-wg4q security advisory: Microsoft Security Advisory CVE-2026-47302 – .NET Denial of Service Vulnerability.

Patch releases

Component Version Where to get it
NServiceBus.Transport.AzureServiceBus 6.2.3 NuGet
NServiceBus.Transport.AzureServiceBus.CommandLine 6.2.3 NuGet or dotnet tool update --g NServiceBus.Transport.AzureServiceBus.CommandLine --v 6.2.3
NServiceBus.Transport.AzureServiceBus 6.3.1 NuGet
NServiceBus.Transport.AzureServiceBus.CommandLine 6.3.1 NuGet or dotnet tool update --g NServiceBus.Transport.AzureServiceBus.CommandLine --v 6.3.1
ServiceInsight 2.13.3 The Download Page

How to know if you are affected

You are affected if you are using previous versions of any of these components, but this doesn’t necessarily mean you are vulnerable.

Symptoms

For NuGet packages your projects have the setting NuGetAuditMode set to all and see transitive dependency warnings at build time that mention Particular packages.

Other components of the platform will not have any symptoms.

When to upgrade

You should upgrade immediately if you are affected. Otherwise, you should upgrade during your next maintenance window.

Dependency Vulnerability Process

The process Particular Software follows for addressing vulnerabilities in dependencies is documented on the Particular docs site.

With thanks,
The team in Particular