HIGH 7.5 NuGet
CoreWCF: Pre-authentication infinite-loop CPU exhaustion in CoreWCF net.tcp / net.pipe / net.uds framing handshake
GHSA-p86g-xrr2-pf7c · CVE-2026-54772
Published · Modified
Description
Impact
An unauthenticated remote attacker can pin one server thread‑pool worker at 100 % CPU per connection. With a few connections, the CPU usage can be exhausted.
Preconditions
An attacker being able to reach a service which is exposing an endpoint using one of NetTcpBinding, NetNamedPipeBinding, or UnixDomainSocketBinding.
Patches
Fixed in CoreWCF v1.8.1 and v1.9.1
Workarounds
None
Ready to move
Start Securing
Free, no credit card | First findings in minutes