CoreWCF.Primitives
NuGet8 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting CoreWCF.Primitivespage 1 of 1
- CVE-2026-54773MEDIUMCVSS 5.9EG 5.9fixed in 1.8.1 or 1.9.1, by version range2026-06-19
vulnerable: 1.9.0
CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF WS-Security signature verification performs a document-wide ds:Signature lookup, allowing an unauthenticated re…
- CVE-2026-54774HIGHCVSS 7.4EG 7.4fixed in 1.8.1 or 1.9.1, by version range2026-06-19
vulnerable: 1.9.0
CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, SamlSerializer skips final SignatureValue verification when a CoreWCF service validates SAML tokens using a non-X.509 s…
- CVE-2026-54779MEDIUMCVSS 5.9EG 5.9fixed in 1.8.1 or 1.9.1, by version range2026-06-19
vulnerable: 1.9.0
CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF SAML token replay protection is inoperative because DefaultTokenReplayCache.TryAdd does not reject duplicate to…
- CVE-2026-54780LOWCVSS 3.7EG 3.7fixed in 1.8.1 or 1.9.1, by version range2026-06-19
vulnerable: 1.9.0
CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, the CoreWCF WS-Security 1.0 receive pipeline validates ds:SignedInfo SignatureMethod against the configured SecurityAlg…
- CVE-2026-54781HIGHCVSS 7.4EG 7.4fixed in 1.8.1 or 1.9.1, by version range2026-06-19
vulnerable: 1.9.0
CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF SAML token validation does not enforce SubjectConfirmation method URIs or holder-of-key proof keys in SamlSecur…
- CVE-2026-54782CRITICALCVSS 10.0EG 10.0fixed in 1.8.1 or 1.9.1, by version range2026-06-19
vulnerable: 1.9.0
CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF SAML 1.1 and SAML 2.0 token validation does not correctly resolve the issuer signing key or require signed toke…
- CVE-2026-54783HIGHCVSS 7.4EG 7.4fixed in 1.8.1 or 1.9.1, by version range2026-06-19
vulnerable: 1.9.0
CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF WS-Security endorsing and supporting signature verification does not ensure the selected ds:Signature covers th…
- CVE-2026-54784HIGHCVSS 7.4EG 7.4fixed in 1.9.12026-06-19
vulnerable: 1.9.0
CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. In version 1.9.0, CoreWCF SPNEGO SecurityContextToken negotiation can expose the proof key recovered from the RSTR when TransportWithMessageCrede…
Check whether CoreWCF.Primitives is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for CoreWCF.Primitives CVEs against the assets you own.
Book a Demo →