Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
CVE-2026-54782
  • github.com/corewcf/corewcf
CoreWCF: Authentication bypass in CoreWCF SAML 1.1 / 2.0 token signature validation 08 Jul
  • Fix available
  • Severity - 10.0 (Critical)
CVE-2026-54781
  • github.com/corewcf/corewcf
CoreWCF: SAML SubjectConfirmation methods and holder-of-key proof keys are not enforced 08 Jul
  • Fix available
  • Severity - 7.4 (High)
CVE-2026-54784
  • github.com/corewcf/corewcf
CoreWCF: SPNEGO SecurityContextToken proof key wrapped without confidentiality 08 Jul
  • Fix available
  • Severity - 7.4 (High)
CVE-2026-54774
  • github.com/corewcf/corewcf
CoreWCF: SamlSerializer skips SignatureValue verification when SAML signing token is not an X.509 certificate 08 Jul
  • Fix available
  • Severity - 7.4 (High)
CVE-2026-54783
  • github.com/corewcf/corewcf
CoreWCF: XML Signature Wrapping in WS-Security endorsing/supporting signature verification allows replay of captured signed messages 08 Jul
  • Fix available
  • Severity - 7.4 (High)
CVE-2026-54780
  • github.com/corewcf/corewcf
CoreWCF: WS-Security Reference DigestMethod Algorithm-Suite Bypass 08 Jul
  • Fix available
  • Severity - 3.7 (Low)
CVE-2026-54775
  • github.com/corewcf/corewcf
CoreWCF: Kafka consume pump halts permanently on a Kafka tombstone (null-value record), causing persistent endpoint denial of service. 08 Jul
  • Fix available
  • Severity - 6.5 (Medium)
CVE-2026-54778
  • github.com/corewcf/corewcf
CoreWCF: UnixDomainSocket Non-Reentrant POSIX Identity Resolution 08 Jul
  • Fix available
  • Severity - 6.2 (Medium)
CVE-2026-54773
  • github.com/corewcf/corewcf
CoreWCF: WS-Security signature substitution via document-wide Signature lookup 08 Jul
  • Fix available
  • Severity - 5.9 (Medium)
CVE-2026-54779
  • github.com/corewcf/corewcf
CoreWCF: SAML token replay protection is inoperative 08 Jul
  • Fix available
  • Severity - 5.9 (Medium)
CVE-2026-54772
  • github.com/corewcf/corewcf
CoreWCF: Pre-authentication infinite-loop CPU exhaustion in CoreWCF net.tcp / net.pipe / net.uds framing handshake 08 Jul
  • Fix available
  • Severity - 7.5 (High)
CVE-2026-54776
  • github.com/corewcf/corewcf
CoreWCF: Unix Domain Socket PosixIdentity transport accepts connections that skip the security upgrade 08 Jul
  • Fix available
  • Severity - 4.4 (Medium)
CVE-2026-54777
  • github.com/corewcf/corewcf
CoreWCF NetNamedPipe transport accepts attach to a pre-existing named pipe instance 08 Jul
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-2288-8h3r-cqgg
  • NuGet/CoreWCF.Primitives
CoreWCF: SPNEGO SecurityContextToken proof key wrapped without confidentiality 19 Jun
  • Fix available
  • Severity - 7.4 (High)
GHSA-gqv6-pwcg-87r8
  • NuGet/CoreWCF.Primitives
CoreWCF: XML Signature Wrapping in WS-Security endorsing/supporting signature verification allows replay of captured signed messages 19 Jun
  • Fix available
  • Severity - 7.4 (High)
GHSA-xjr9-gg9q-jx3v
  • NuGet/CoreWCF.Primitives
CoreWCF: Authentication bypass in CoreWCF SAML 1.1 / 2.0 token signature validation 19 Jun
  • Fix available
  • Severity - 10.0 (Critical)