<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 10:47:00 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-335520</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-335520</link>
      <description>EUVD-2026-335520</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-335520</guid>
    </item>
    <item>
      <title>fkie_cve-2026-54777</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-54777</link>
      <description>&lt;p&gt;CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF NetNamedPipe transport accepts attachment to a pre-existing named pipe instance, allowing local interception of NetNamedPipe traffic when an attacker races NamedPipeListener startup between shared memory GUID publication and service named pipe creation. This issue is fixed in versions 1.8.1 and 1.9.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF NetNamedPipe transport accepts attachment to a pre-existing named pipe instance, allowing local interception of NetNamedPipe traffic when an attacker races NamedPipeListener startup between shared memory GUID publication and service named pipe creation. This issue is fixed in versions 1.8.1 and 1.9.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-54777</guid>
    </item>
    <item>
      <title>GHSA-6jj2-4q5c-x8g6 — CoreWCF NetNamedPipe transport accepts attach to a pre-existing named pipe instance</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-6jj2-4q5c-x8g6</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; NuGet: CoreWCF.NetNamedPipe&lt;/p&gt;
&lt;p&gt;### Impact
CoreWCF NetNamedPipe transport accepts attach to a pre-existing named pipe instance, allowing local interception of NetNamedPipe traffic. NetNamedPipe creates a shared memory object based on the listening url, then generated a unique GUID for the named pipe it will be using and saves this to the shared memory object. Then it creates the named pipe to listen for clients. This requires an attacker to race the service and create the named pipe between the service publishing the GUID to the shared memory location (which the attacker needs to read) and the service creating the named pipe itself.&lt;/p&gt;
&lt;p&gt;### Patches
Fixed in CoreWCF v1.8.1 and v1.9.1&lt;/p&gt;
&lt;p&gt;### Workarounds
None&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; NuGet: CoreWCF.NetNamedPipe&lt;/p&gt;
&lt;p&gt;### Impact
CoreWCF NetNamedPipe transport accepts attach to a pre-existing named pipe instance, allowing local interception of NetNamedPipe traffic. NetNamedPipe creates a shared memory object based on the listening url, then generated a unique GUID for the named pipe it will be using and saves this to the shared memory object. Then it creates the named pipe to listen for clients. This requires an attacker to race the service and create the named pipe between the service publishing the GUID to the shared memory location (which the attacker needs to read) and the service creating the named pipe itself.&lt;/p&gt;
&lt;p&gt;### Patches
Fixed in CoreWCF v1.8.1 and v1.9.1&lt;/p&gt;
&lt;p&gt;### Workarounds
None&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-6jj2-4q5c-x8g6</guid>
    </item>
  </channel>
</rss>
