CVE-2026-54775: Corewcf

Medium severity, CVSS 6.5. EPSS: 0.6% chance of exploitation in the next 30 days.

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, a CoreWCF service listening on a Kafka topic stops processing new records from that topic when KafkaTransportPump receives a null-value tombstone record, causing a persistent endpoint denial of service for attackers with produce permission. This issue is fixed in versions 1.8.1 and 1.9.1.

Affected products

  • Corewcf Corewcf: from 1.9.0, before 1.9.1 (fixed in 1.9.1); before 1.8.1 (fixed in 1.8.1)

Published 2026-07-08. Last modified 2026-07-09.