### Impact A CoreWCF service is running and listening on a Kafka topic receiving a null-value record will stop processing new records from that topic. #### Preconditions The attacker has produce/write permission on a topic that CoreWCF is consuming from. If the broker permits anonymous publishes, no authentication is required. ### Patches Fixed in CoreWCF v1.8.1 and v1.9.1 ### Workarounds Only allow authenticated writes to a topic
Update CoreWCF.Kafka to 1.8.1; CoreWCF.Kafka to 1.9.1 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanCoreWCF: Kafka consume pump halts permanently on a Kafka tombstone (null-value record), causing persistent endpoint denial of service. affects CoreWCF.Kafka (nuget), CoreWCF.Kafka (nuget). Severity is medium. ### Impact A CoreWCF service is running and listening on a Kafka topic receiving a null-value record will stop processing new records from that topic. #### Preconditions The attacker has produce/write permission on a topic that CoreWCF is consuming from. If the broker permits anonymous publishes, no authentication is required. ### Patches Fixed in CoreWCF v1.8.1 and v1.9.1 ### Workarounds Only allow authenticated writes to a topic
AI coding agents often install or upgrade packages automatically in nuget. A medium vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| CoreWCF.Kafkanuget |
### Impact A CoreWCF service is running and listening on a Kafka topic receiving a null-value record will stop processing new records from that topic. #### Preconditions The attacker has produce/write permission on a topic that CoreWCF is consuming from. If the broker permits anonymous publishes, no authentication is required. ### Patches Fixed in CoreWCF v1.8.1 and v1.9.1 ### Workarounds Only allow authenticated writes to a topic
Update CoreWCF.Kafka to 1.8.1; CoreWCF.Kafka to 1.9.1 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanCoreWCF: Kafka consume pump halts permanently on a Kafka tombstone (null-value record), causing persistent endpoint denial of service. affects CoreWCF.Kafka (nuget), CoreWCF.Kafka (nuget). Severity is medium. ### Impact A CoreWCF service is running and listening on a Kafka topic receiving a null-value record will stop processing new records from that topic. #### Preconditions The attacker has produce/write permission on a topic that CoreWCF is consuming from. If the broker permits anonymous publishes, no authentication is required. ### Patches Fixed in CoreWCF v1.8.1 and v1.9.1 ### Workarounds Only allow authenticated writes to a topic
AI coding agents often install or upgrade packages automatically in nuget. A medium vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| CoreWCF.Kafkanuget |
| <1.8.1 |
| 1.8.1 |
| CoreWCF.Kafkanuget | >=1.9.0,<1.9.1 | 1.9.1 |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| <1.8.1 |
| 1.8.1 |
| CoreWCF.Kafkanuget | >=1.9.0,<1.9.1 | 1.9.1 |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard