CVE-2026-54775Medium· 6.5▾ SunlitCoreWCF: Kafka consume pump halts permanently on a Kafka tombstone (null-value record), causing persistent endpoint denial of service.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 9.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
0.3%
0.3% → 0.6%
A CoreWCF service is running and listening on a Kafka topic receiving a null-value record will stop processing new records from that topic.
The attacker has produce/write permission on a topic that CoreWCF is consuming from. If the broker permits anonymous publishes, no authentication is required.
Fixed in CoreWCF v1.8.1 and v1.9.1
Only allow authenticated writes to a topic
CoreWCF.Kafka < 1.8.1CoreWCF.Kafka >= 1.9.0, < 1.9.1Upgrade to a patched release:
CoreWCF.Kafka 1.8.1CoreWCF.Kafka 1.9.1Connected by shared product, vendor, weakness, or advisory.
GHSA-pfvm-w89x-94jwHigh· 7.5SIPSorcery: Malformed UDP datagram crashes TurnServer receive loop with no restart, disabling TURN UDP relay for all clients (DoS)
CVE-2026-85014Medium· 5.9undici's experimental WebSocketStream client crashes the whole Node.js process when a remote peer closes the TCP connection without a WebSocket close handshake
CVE-2026-55484High· 7.5ALOS HTTP is a Linux-first Go web framework and application server built around a custom networking stack
CVE-2024-6594High· 7.5Improper Handling of Exceptional Conditions vulnerability in the WatchGuard Single Sign-On Client on Windows causes the client to crash while handling malformed commands
CVE-2023-5090Medium· 6.0A flaw was found in KVM
CVE-2026-44001High· 8.6vm2 is an open source vm/sandbox for Node.js