SignalR has an Information Disclosure vulnerability. If you use the Redis backplane in SignalR it is possible to listen to any group or user with a specially crafted group/user name.
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2023-35391