GHSA-4v55-cpmv-3vcm

Suggest an improvement
Source
https://github.com/advisories/GHSA-4v55-cpmv-3vcm
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-4v55-cpmv-3vcm/GHSA-4v55-cpmv-3vcm.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-4v55-cpmv-3vcm
Aliases
  • CVE-2026-54780
Published
2026-06-19T20:47:04Z
Modified
2026-06-19T21:00:18.130062916Z
Severity
  • 3.7 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N CVSS Calculator
Summary
CoreWCF: WS-Security Reference DigestMethod Algorithm-Suite Bypass
Details

Impact

CoreWCF’s WS-Security 1.0 receive pipeline validates the SignatureMethod of an incoming ds:SignedInfo against the configured SecurityAlgorithmSuite, but does not validate the DigestMethod declared on each ds:Reference. As a result, a sender can populate ds:SignedInfo with SignatureMethod values the suite accepts (for example rsa-sha256 under Basic256Sha256) while declaring a per-reference DigestMethod the suite rejects (for example http://www.w3.org/2000/09/xmldsig#sha1). The signature is then verified where it permits SHA-1 digests, and the message is accepted.

Patches

Fixed in CoreWCF v1.8.1 and v1.9.1

Workarounds

None

Database specific
{
    "nvd_published_at": null,
    "github_reviewed_at": "2026-06-19T20:47:04Z",
    "github_reviewed": true,
    "severity": "LOW",
    "cwe_ids": [
        "CWE-327",
        "CWE-757"
    ]
}
References

Affected packages

NuGet / CoreWCF.Primitives

Package

Name
CoreWCF.Primitives
View open source insights on deps.dev
Purl
pkg:nuget/CoreWCF.Primitives

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.8.1

Affected versions

0.*
0.1.0-preview
0.1.0-preview-2
0.1.0
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
1.*
1.0.0-preview1
1.0.0-preview2
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0-preview1
1.4.0
1.4.1
1.4.2
1.5.0-preview1
1.5.0
1.5.1
1.5.2
1.6.0
1.7.0
1.8.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-4v55-cpmv-3vcm/GHSA-4v55-cpmv-3vcm.json"

NuGet / CoreWCF.Primitives

Package

Name
CoreWCF.Primitives
View open source insights on deps.dev
Purl
pkg:nuget/CoreWCF.Primitives

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.9.0
Fixed
1.9.1

Affected versions

1.*
1.9.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-4v55-cpmv-3vcm/GHSA-4v55-cpmv-3vcm.json"