{"id":"CVE-2026-54775","title":"CoreWCF: Kafka consume pump halts permanently on a Kafka tombstone (null-value record), causing persistent endpoint denial of service.","summary":"CoreWCF: Kafka consume pump halts permanently on a Kafka tombstone (null-value record), causing persistent endpoint denial of service.","severity":"medium","cvss":6.5,"cwe":["CWE-248","CWE-754","CWE-755"],"vendor":"CoreWCF","product":"CoreWCF.Kafka","ecosystem":"nuget","affected":["CoreWCF.Kafka < 1.8.1","CoreWCF.Kafka >= 1.9.0, < 1.9.1"],"patched":["CoreWCF.Kafka 1.8.1","CoreWCF.Kafka 1.9.1"],"published":"2026-06-19","updated":"2026-06-19","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-m744-jhq9-ppw6","references":[{"url":"https://github.com/CoreWCF/CoreWCF/security/advisories/GHSA-m744-jhq9-ppw6"},{"url":"https://github.com/advisories/GHSA-m744-jhq9-ppw6"}],"tags":["ghsa","nuget"],"ingestedAt":"2026-06-22T13:35:24.437Z","epss":0.00598,"epssPercentile":0.47043,"slug":"CVE-2026-54775","body":"## Overview\n\n### Impact\nA CoreWCF service is running and listening on a Kafka topic receiving a null-value record will stop processing new records from that topic.\n\n#### Preconditions\nThe attacker has produce/write permission on a topic that CoreWCF is consuming from. If the broker permits anonymous publishes, no authentication is required. \n\n### Patches\nFixed in CoreWCF v1.8.1 and v1.9.1\n\n### Workarounds\nOnly allow authenticated writes to a topic\n\n## Affected packages\n\n- `CoreWCF.Kafka < 1.8.1`\n- `CoreWCF.Kafka >= 1.9.0, < 1.9.1`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `CoreWCF.Kafka 1.8.1`\n- `CoreWCF.Kafka 1.9.1`","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}