CVE-2026-54775

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, a CoreWCF service listening on a Kafka topic stops processing new records from that topic when KafkaTransportPump receives a null-value tombstone record, causing a persistent endpoint denial of service for attackers with produce permission. This issue is fixed in versions 1.8.1 and 1.9.1.
Configurations

No configuration.

History

08 Jul 2026, 23:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-08 23:16

Updated : 2026-07-09 16:29


NVD link : CVE-2026-54775

Mitre link : CVE-2026-54775

CVE.ORG link : CVE-2026-54775


JSON object : View

Products Affected

No product.

CWE
CWE-248

Uncaught Exception

CWE-754

Improper Check for Unusual or Exceptional Conditions

CWE-755

Improper Handling of Exceptional Conditions