CVE-2026-54772: Corewcf

High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, an unauthenticated remote attacker that can reach a NetTcpBinding, NetNamedPipeBinding, or UnixDomainSocketBinding endpoint can trigger premature EOF handling in the CoreWCF net.tcp, net.pipe, or net.uds framing handshake and pin one server thread-pool worker at full CPU per connection. This issue is fixed in versions 1.8.1 and 1.9.1.

Affected products

  • Corewcf Corewcf: from 1.9.0, before 1.9.1 (fixed in 1.9.1); before 1.8.1 (fixed in 1.8.1)

Published 2026-07-08. Last modified 2026-07-09.