Executive brief
CoreWCF is a library used to build web services on .NET Core. A vulnerability in how it handles network connections allows an unauthenticated attacker to force the server into an infinite loop. This can cause the server's processor to reach 100% usage, potentially making the service slow or completely unavailable to legitimate users.
Technical details
A denial-of-service vulnerability exists in CoreWCF due to improper handling of premature End-of-File (EOF) conditions during the framing handshake. An unauthenticated remote attacker can reach a NetTcpBinding, NetNamedPipeBinding, or UnixDomainSocketBinding endpoint and trigger a loop with an unreachable exit condition (CWE-835). This results in one server thread-pool worker being pinned at 100% CPU per malicious connection, leading to uncontrolled resource consumption (CWE-400). The issue is fixed in CoreWCF versions 1.8.1 and 1.9.1.
Affected products
- CoreWCF CoreWCF.NetFramingBase < 1.8.1, >= 1.9.0 < 1.9.1
Timeline
- 2026-06-16: advisory: GitHub Security Advisory published
- 2026-06-16: patched: Versions 1.8.1 and 1.9.1 released
- 2026-07-08: disclosed: NVD publication date
References
- https://github.com/CoreWCF/CoreWCF/commit/03ddbced349931a2da6c0efcdf745c0722eff77c
- https://github.com/CoreWCF/CoreWCF/commit/7ddd966d6e58564a32ab30c825dd693b45a34a55
- https://github.com/CoreWCF/CoreWCF/commit/c4212988cd6fd472783d0413426eeac61044097a
- https://github.com/CoreWCF/CoreWCF/releases/tag/v1.8.1
- https://github.com/CoreWCF/CoreWCF/releases/tag/v1.9.1
- https://github.com/CoreWCF/CoreWCF/security/advisories/GHSA-p86g-xrr2-pf7c