PT-2026-51069 · Corewcf+2 · Corewcf+1
CVE-2026-54772
·
Published
2026-06-19
·
Updated
2026-07-09
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
CoreWCF versions prior to 1.8.1
CoreWCF versions prior to 1.9.1
Description
An unauthenticated remote attacker can trigger premature EOF (End of File) handling during the framing handshake of the net.tcp, net.pipe, or net.uds components. This occurs when the attacker can reach endpoints using NetTcpBinding, NetNamedPipeBinding, or UnixDomainSocketBinding, allowing them to pin one server thread-pool worker at full CPU capacity per connection. Consequently, a small number of connections can exhaust the server CPU resources.
Recommendations
Update CoreWCF to version 1.8.1.
Update CoreWCF to version 1.9.1.
Exploit
Fix
Infinite Loop
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Corewcf
Corewcf.Netframingbase