CVE Explorer
CVE-2026-54775
CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, a CoreWCF service listening on a Kafka topic stops processing new records from that topic when KafkaTransportPump receives a null-value tombstone record, causing a persistent endpoint denial of service for attackers with produce permission. This issue is fixed in versions 1.8.1 and 1.9.1.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 3 assertions
{"cweId":"CWE-755","description":"CWE-755: Improper Handling of Exceptional Conditions","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:d6f0469e85fbf0630cfa62119e5eedc687507a81cd677618def2c235bc64bf5b · sha256:17484f9ed05d9582… · /containers/cna/problemTypes/2/descriptions/0
{"cweId":"CWE-248","description":"CWE-248: Uncaught Exception","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:d6f0469e85fbf0630cfa62119e5eedc687507a81cd677618def2c235bc64bf5b · sha256:17484f9ed05d9582… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-754","description":"CWE-754: Improper Check for Unusual or Exceptional Conditions","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:d6f0469e85fbf0630cfa62119e5eedc687507a81cd677618def2c235bc64bf5b · sha256:17484f9ed05d9582… · /containers/cna/problemTypes/1/descriptions/0
Affected products and versions
1 source assertion{"product":"CoreWCF","vendor":"CoreWCF","versions":[{"status":"affected","version":">= 1.9.0, < 1.9.1"},{"status":"affected","version":"< 1.8.1"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:d6f0469e85fbf0630cfa62119e5eedc687507a81cd677618def2c235bc64bf5b · sha256:17484f9ed05d9582… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:d6f0469e85fbf0630cfa62119e5eedc687507a81cd677618def2c235bc64bf5b · sha256:17484f9ed05d9582… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
3 source assertions{"cweId":"CWE-755","description":"CWE-755: Improper Handling of Exceptional Conditions","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:d6f0469e85fbf0630cfa62119e5eedc687507a81cd677618def2c235bc64bf5b · sha256:17484f9ed05d9582… · /containers/cna/problemTypes/2/descriptions/0
{"cweId":"CWE-248","description":"CWE-248: Uncaught Exception","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:d6f0469e85fbf0630cfa62119e5eedc687507a81cd677618def2c235bc64bf5b · sha256:17484f9ed05d9582… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-754","description":"CWE-754: Improper Check for Unusual or Exceptional Conditions","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:d6f0469e85fbf0630cfa62119e5eedc687507a81cd677618def2c235bc64bf5b · sha256:17484f9ed05d9582… · /containers/cna/problemTypes/1/descriptions/0
Source references
6 source assertions{"name":"https://github.com/CoreWCF/CoreWCF/commit/1a229d0d14a07766302f7d14c866889f04a3a624","tags":["x_refsource_MISC"],"url":"https://github.com/CoreWCF/CoreWCF/commit/1a229d0d14a07766302f7d14c866889f04a3a624"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d6f0469e85fbf0630cfa62119e5eedc687507a81cd677618def2c235bc64bf5b · sha256:17484f9ed05d9582… · /containers/cna/references/1
{"name":"https://github.com/CoreWCF/CoreWCF/commit/6d7431ebc0ebe6521ea6d0dbea8982bac3d2bc98","tags":["x_refsource_MISC"],"url":"https://github.com/CoreWCF/CoreWCF/commit/6d7431ebc0ebe6521ea6d0dbea8982bac3d2bc98"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d6f0469e85fbf0630cfa62119e5eedc687507a81cd677618def2c235bc64bf5b · sha256:17484f9ed05d9582… · /containers/cna/references/2
{"name":"https://github.com/CoreWCF/CoreWCF/commit/8f95f3ac3c929409e830b5c5659683ef9f6ea6b0","tags":["x_refsource_MISC"],"url":"https://github.com/CoreWCF/CoreWCF/commit/8f95f3ac3c929409e830b5c5659683ef9f6ea6b0"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d6f0469e85fbf0630cfa62119e5eedc687507a81cd677618def2c235bc64bf5b · sha256:17484f9ed05d9582… · /containers/cna/references/3
{"name":"https://github.com/CoreWCF/CoreWCF/releases/tag/v1.8.1","tags":["x_refsource_MISC"],"url":"https://github.com/CoreWCF/CoreWCF/releases/tag/v1.8.1"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d6f0469e85fbf0630cfa62119e5eedc687507a81cd677618def2c235bc64bf5b · sha256:17484f9ed05d9582… · /containers/cna/references/4
{"name":"https://github.com/CoreWCF/CoreWCF/releases/tag/v1.9.1","tags":["x_refsource_MISC"],"url":"https://github.com/CoreWCF/CoreWCF/releases/tag/v1.9.1"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d6f0469e85fbf0630cfa62119e5eedc687507a81cd677618def2c235bc64bf5b · sha256:17484f9ed05d9582… · /containers/cna/references/5
{"name":"https://github.com/CoreWCF/CoreWCF/security/advisories/GHSA-m744-jhq9-ppw6","tags":["x_refsource_CONFIRM"],"url":"https://github.com/CoreWCF/CoreWCF/security/advisories/GHSA-m744-jhq9-ppw6"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d6f0469e85fbf0630cfa62119e5eedc687507a81cd677618def2c235bc64bf5b · sha256:17484f9ed05d9582… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.