Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2242916
AlmaLinux
5975
Alpaquita
16181
Alpine
4655
Android
3708
Azure Linux
17971
BellSoft Hardened Containers
771
Bitnami
9501
Chainguard
1048720
CleanStart
5479
CRAN
14
crates.io
2768
Debian
69013
Echo
7867
GHC
3
GIT
109123
GitHub Actions
55
Go
9332
Hackage
33
Hex
367
Julia
1713
Linux
29975
Mageia
6237
Maven
7055
MinimOS
148690
npm
229272
NuGet
1869
opam
29
openEuler
8900
openSUSE
14647
OSS-Fuzz
4019
Packagist
7103
Pub
11
PyPI
25495
Red Hat
23535
Rocky Linux
4354
Root
19660
RubyGems
5369
SUSE
23455
SwiftURL
61
TuxCare
9977
Ubuntu
66090
VSCode
21
Wolfi
293843
ID
Packages
Summary
Published
arrow_upward
Attributes
CVE-2026-54782
github.com/corewcf/corewcf
CoreWCF: Authentication bypass in CoreWCF SAML 1.1 / 2.0 token signature validation
08 Jul
Fix available
Severity - 10.0 (Critical)
CVE-2026-54781
github.com/corewcf/corewcf
CoreWCF: SAML SubjectConfirmation methods and holder-of-key proof keys are not enforced
08 Jul
Fix available
Severity - 7.4 (High)
CVE-2026-54784
github.com/corewcf/corewcf
CoreWCF: SPNEGO SecurityContextToken proof key wrapped without confidentiality
08 Jul
Fix available
Severity - 7.4 (High)
CVE-2026-54774
github.com/corewcf/corewcf
CoreWCF: SamlSerializer skips SignatureValue verification when SAML signing token is not an X.509 certificate
08 Jul
Fix available
Severity - 7.4 (High)
CVE-2026-54783
github.com/corewcf/corewcf
CoreWCF: XML Signature Wrapping in WS-Security endorsing/supporting signature verification allows replay of captured signed messages
08 Jul
Fix available
Severity - 7.4 (High)
CVE-2026-54780
github.com/corewcf/corewcf
CoreWCF: WS-Security Reference DigestMethod Algorithm-Suite Bypass
08 Jul
Fix available
Severity - 3.7 (Low)
CVE-2026-54775
github.com/corewcf/corewcf
CoreWCF: Kafka consume pump halts permanently on a Kafka tombstone (null-value record), causing persistent endpoint denial of service.
08 Jul
Fix available
Severity - 6.5 (Medium)
CVE-2026-54778
github.com/corewcf/corewcf
CoreWCF: UnixDomainSocket Non-Reentrant POSIX Identity Resolution
08 Jul
Fix available
Severity - 6.2 (Medium)
CVE-2026-54773
github.com/corewcf/corewcf
CoreWCF: WS-Security signature substitution via document-wide Signature lookup
08 Jul
Fix available
Severity - 5.9 (Medium)
CVE-2026-54779
github.com/corewcf/corewcf
CoreWCF: SAML token replay protection is inoperative
08 Jul
Fix available
Severity - 5.9 (Medium)
CVE-2026-54772
github.com/corewcf/corewcf
CoreWCF: Pre-authentication infinite-loop CPU exhaustion in CoreWCF net.tcp / net.pipe / net.uds framing handshake
08 Jul
Fix available
Severity - 7.5 (High)
CVE-2026-54776
github.com/corewcf/corewcf
CoreWCF: Unix Domain Socket PosixIdentity transport accepts connections that skip the security upgrade
08 Jul
Fix available
Severity - 4.4 (Medium)
CVE-2026-54777
github.com/corewcf/corewcf
CoreWCF NetNamedPipe transport accepts attach to a pre-existing named pipe instance
08 Jul
Fix available
Severity - 6.5 (Medium)
GHSA-2288-8h3r-cqgg
NuGet/CoreWCF.Primitives
CoreWCF: SPNEGO SecurityContextToken proof key wrapped without confidentiality
19 Jun
Fix available
Severity - 7.4 (High)
GHSA-gqv6-pwcg-87r8
NuGet/CoreWCF.Primitives
CoreWCF: XML Signature Wrapping in WS-Security endorsing/supporting signature verification allows replay of captured signed messages
19 Jun
Fix available
Severity - 7.4 (High)
GHSA-xjr9-gg9q-jx3v
NuGet/CoreWCF.Primitives
CoreWCF: Authentication bypass in CoreWCF SAML 1.1 / 2.0 token signature validation
19 Jun
Fix available
Severity - 10.0 (Critical)
Load more...
Vulnerability Database - OSV