PT-2026-51069 · Corewcf+2 · Corewcf+1

CVE-2026-54772

·

Published

2026-06-19

·

Updated

2026-07-09

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions CoreWCF versions prior to 1.8.1 CoreWCF versions prior to 1.9.1
Description An unauthenticated remote attacker can trigger premature EOF (End of File) handling during the framing handshake of the net.tcp, net.pipe, or net.uds components. This occurs when the attacker can reach endpoints using NetTcpBinding, NetNamedPipeBinding, or UnixDomainSocketBinding, allowing them to pin one server thread-pool worker at full CPU capacity per connection. Consequently, a small number of connections can exhaust the server CPU resources.
Recommendations Update CoreWCF to version 1.8.1. Update CoreWCF to version 1.9.1.

Exploit

Fix

Infinite Loop

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54772
GHSA-P86G-XRR2-PF7C

Affected Products

Corewcf
Corewcf.Netframingbase