CVE-2026-54778
MEDIUMCoreWCF: UnixDomainSocket Non-Reentrant POSIX Identity Resolution
Title source: cnaDescription
CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF UnixDomainSocket POSIX peer identity resolution uses non-reentrant getpwuid and getgrgid calls, allowing concurrent connections to attribute one connection's identity to another or crash the host process under contention. This issue is fixed in versions 1.8.1 and 1.9.1.
References (6)
Core 6
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/CoreWCF/CoreWCF/security/advisories/GHSA-q6v9-43v5-jv9q
X_Refsource_Misc x_refsource_misc
https://github.com/CoreWCF/CoreWCF/commit/a3d95ea4627b818995e92c7def4c016164cacfce
X_Refsource_Misc x_refsource_misc
https://github.com/CoreWCF/CoreWCF/commit/b0acb105589b455a095ea5ff49f5191e4eeff791
X_Refsource_Misc x_refsource_misc
https://github.com/CoreWCF/CoreWCF/commit/b4867547c94bb088568935d581a55dda18a621e1
X_Refsource_Misc x_refsource_misc
https://github.com/CoreWCF/CoreWCF/releases/tag/v1.8.1
X_Refsource_Misc x_refsource_misc
https://github.com/CoreWCF/CoreWCF/releases/tag/v1.9.1
Scores
CVSS v3
6.2
EPSS
0.0010
EPSS Percentile
1.0%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-362
CWE-825
Status
published
Products (2)
CoreWCF/CoreWCF
< 1.8.1
CoreWCF/CoreWCF
>= 1.9.0, < 1.9.1
Published
Jul 08, 2026
Tracked Since
Jul 09, 2026