Junglewise Threat Intelligence

CVE-2026-54772: CoreWCF infinite loop CPU exhaustion in framing handshake

CVE-2026-54772 · Severity: high · CVSS 7.5 · Published 2026-07-08

Vendors: CoreWCF.

Executive brief

CoreWCF is a library used to build web services on .NET Core. A vulnerability in how it handles network connections allows an unauthenticated attacker to force the server into an infinite loop. This can cause the server's processor to reach 100% usage, potentially making the service slow or completely unavailable to legitimate users.

Technical details

A denial-of-service vulnerability exists in CoreWCF due to improper handling of premature End-of-File (EOF) conditions during the framing handshake. An unauthenticated remote attacker can reach a NetTcpBinding, NetNamedPipeBinding, or UnixDomainSocketBinding endpoint and trigger a loop with an unreachable exit condition (CWE-835). This results in one server thread-pool worker being pinned at 100% CPU per malicious connection, leading to uncontrolled resource consumption (CWE-400). The issue is fixed in CoreWCF versions 1.8.1 and 1.9.1.

Affected products

  • CoreWCF CoreWCF.NetFramingBase < 1.8.1, >= 1.9.0 < 1.9.1

Timeline

  • 2026-06-16: advisory: GitHub Security Advisory published
  • 2026-06-16: patched: Versions 1.8.1 and 1.9.1 released
  • 2026-07-08: disclosed: NVD publication date

References