- EPSS 0.25%
- Veröffentlicht 08.07.2026 22:20:37
- Zuletzt bearbeitet 10.07.2026 05:16:37
CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF SAML 1.1 and SAML 2.0 token validation does not correctly resolve the issuer signing key or require signed tokens when Ide...
CVE-2026-54781
- EPSS 0.18%
- Veröffentlicht 08.07.2026 22:19:40
- Zuletzt bearbeitet 09.07.2026 16:29:14
CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF SAML token validation does not enforce SubjectConfirmation method URIs or holder-of-key proof keys in SamlSecurityTokenHan...
CVE-2026-54784
- EPSS 0.18%
- Veröffentlicht 08.07.2026 22:18:13
- Zuletzt bearbeitet 10.07.2026 05:16:37
CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. In version 1.9.0, CoreWCF SPNEGO SecurityContextToken negotiation can expose the proof key recovered from the RSTR when TransportWithMessageCredential with ...
CVE-2026-54774
- EPSS 0.15%
- Veröffentlicht 08.07.2026 22:17:07
- Zuletzt bearbeitet 10.07.2026 05:16:37
CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, SamlSerializer skips final SignatureValue verification when a CoreWCF service validates SAML tokens using a non-X.509 signing toke...
CVE-2026-54783
- EPSS 0.14%
- Veröffentlicht 08.07.2026 22:16:08
- Zuletzt bearbeitet 10.07.2026 05:16:37
CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF WS-Security endorsing and supporting signature verification does not ensure the selected ds:Signature covers the expected ...
CVE-2026-54780
- EPSS 0.16%
- Veröffentlicht 08.07.2026 22:15:06
- Zuletzt bearbeitet 09.07.2026 20:16:29
CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, the CoreWCF WS-Security 1.0 receive pipeline validates ds:SignedInfo SignatureMethod against the configured SecurityAlgorithmSuite...
CVE-2026-54775
- EPSS 0.34%
- Veröffentlicht 08.07.2026 22:13:37
- Zuletzt bearbeitet 09.07.2026 16:29:14
CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, a CoreWCF service listening on a Kafka topic stops processing new records from that topic when KafkaTransportPump receives a null-...
CVE-2026-54778
- EPSS 0.1%
- Veröffentlicht 08.07.2026 22:11:55
- Zuletzt bearbeitet 09.07.2026 16:29:14
CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF UnixDomainSocket POSIX peer identity resolution uses non-reentrant getpwuid and getgrgid calls, allowing concurrent connec...
CVE-2026-54773
- EPSS 0.24%
- Veröffentlicht 08.07.2026 22:09:32
- Zuletzt bearbeitet 10.07.2026 15:16:41
CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF WS-Security signature verification performs a document-wide ds:Signature lookup, allowing an unauthenticated remote attack...
CVE-2026-54779
- EPSS 0.27%
- Veröffentlicht 08.07.2026 22:07:46
- Zuletzt bearbeitet 09.07.2026 16:29:14
CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF SAML token replay protection is inoperative because DefaultTokenReplayCache.TryAdd does not reject duplicate tokens when D...