An unauthenticated remote attacker can pin one server thread‑pool worker at 100 % CPU per connection. With a few connections, the CPU usage can be exhausted.
An attacker being able to reach a service which is exposing an endpoint using one of NetTcpBinding, NetNamedPipeBinding, or UnixDomainSocketBinding.
Fixed in CoreWCF v1.8.1 and v1.9.1
None
{
"nvd_published_at": null,
"github_reviewed_at": "2026-06-19T20:46:40Z",
"github_reviewed": true,
"severity": "HIGH",
"cwe_ids": [
"CWE-400",
"CWE-835"
]
}