### Impact CoreWCF NetNamedPipe transport accepts attach to a pre-existing named pipe instance, allowing local interception of NetNamedPipe traffic. NetNamedPipe creates a shared memory object based on the listening url, then generated a unique GUID for the named pipe it will be using and saves this to the shared memory object. Then it creates the named pipe to listen for clients. This requires an attacker to race the service and create the named pipe between the service publishing the GUID to the shared memory location (which the attacker needs to read) and the service creating the named pipe itself. ### Patches Fixed in CoreWCF v1.8.1 and v1.9.1 ### Workarounds None
Update CoreWCF.NetNamedPipe to 1.8.1; CoreWCF.NetNamedPipe to 1.9.1 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanCoreWCF NetNamedPipe transport accepts attach to a pre-existing named pipe instance affects CoreWCF.NetNamedPipe (nuget), CoreWCF.NetNamedPipe (nuget). Severity is medium. ### Impact CoreWCF NetNamedPipe transport accepts attach to a pre-existing named pipe instance, allowing local interception of NetNamedPipe traffic. NetNamedPipe creates a shared memory object based on the listening url, then generated a unique GUID for the named pipe it will be using and saves this to the shared memory object. Then it creates the named pipe to listen for clients. This requires an attacker to race the service and create the named pipe between the service publishing the GUID to the shared memory location (which the attacker needs to read) and the service creating the named pipe itself. ### Patches Fixed in CoreWCF v1.8.1 and v1.9.1 ### Workarounds None
AI coding agents often install or upgrade packages automatically in nuget. A medium vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|
### Impact CoreWCF NetNamedPipe transport accepts attach to a pre-existing named pipe instance, allowing local interception of NetNamedPipe traffic. NetNamedPipe creates a shared memory object based on the listening url, then generated a unique GUID for the named pipe it will be using and saves this to the shared memory object. Then it creates the named pipe to listen for clients. This requires an attacker to race the service and create the named pipe between the service publishing the GUID to the shared memory location (which the attacker needs to read) and the service creating the named pipe itself. ### Patches Fixed in CoreWCF v1.8.1 and v1.9.1 ### Workarounds None
Update CoreWCF.NetNamedPipe to 1.8.1; CoreWCF.NetNamedPipe to 1.9.1 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanCoreWCF NetNamedPipe transport accepts attach to a pre-existing named pipe instance affects CoreWCF.NetNamedPipe (nuget), CoreWCF.NetNamedPipe (nuget). Severity is medium. ### Impact CoreWCF NetNamedPipe transport accepts attach to a pre-existing named pipe instance, allowing local interception of NetNamedPipe traffic. NetNamedPipe creates a shared memory object based on the listening url, then generated a unique GUID for the named pipe it will be using and saves this to the shared memory object. Then it creates the named pipe to listen for clients. This requires an attacker to race the service and create the named pipe between the service publishing the GUID to the shared memory location (which the attacker needs to read) and the service creating the named pipe itself. ### Patches Fixed in CoreWCF v1.8.1 and v1.9.1 ### Workarounds None
AI coding agents often install or upgrade packages automatically in nuget. A medium vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|
| CoreWCF.NetNamedPipenuget | <1.8.1 | 1.8.1 |
|---|
| CoreWCF.NetNamedPipenuget | >=1.9.0,<1.9.1 | 1.9.1 |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| CoreWCF.NetNamedPipenuget | <1.8.1 | 1.8.1 |
|---|
| CoreWCF.NetNamedPipenuget | >=1.9.0,<1.9.1 | 1.9.1 |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard