CoreWCF.Primitives
NuGet8 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting CoreWCF.Primitivespage 1 of 1
- CVE-2026-54773MEDIUMCVSS 5.9EG 5.9✓ Fixed in 1.9.12026-06-19
vulnerable: 1.9.0
CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF WS-Security signature verification performs a document-wide ds:Signature lookup, allowing an unauthenticated re…
- CVE-2026-54774HIGHCVSS 7.4EG 7.4✓ Fixed in 1.9.12026-06-19
vulnerable: 1.9.0
CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, SamlSerializer skips final SignatureValue verification when a CoreWCF service validates SAML tokens using a non-X.509 s…
- CVE-2026-54779MEDIUMCVSS 5.9EG 5.9✓ Fixed in 1.9.12026-06-19
vulnerable: 1.9.0
CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF SAML token replay protection is inoperative because DefaultTokenReplayCache.TryAdd does not reject duplicate to…
- CVE-2026-54780LOWCVSS 3.7EG 3.7✓ Fixed in 1.9.12026-06-19
vulnerable: 1.9.0
CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, the CoreWCF WS-Security 1.0 receive pipeline validates ds:SignedInfo SignatureMethod against the configured SecurityAlg…
- CVE-2026-54781HIGHCVSS 7.4EG 7.4✓ Fixed in 1.9.12026-06-19
vulnerable: 1.9.0
CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF SAML token validation does not enforce SubjectConfirmation method URIs or holder-of-key proof keys in SamlSecur…
- CVE-2026-54782CRITICALCVSS 10.0EG 10.0✓ Fixed in 1.9.12026-06-19
vulnerable: 1.9.0
CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF SAML 1.1 and SAML 2.0 token validation does not correctly resolve the issuer signing key or require signed toke…
- CVE-2026-54783HIGHCVSS 7.4EG 7.4✓ Fixed in 1.9.12026-06-19
vulnerable: 1.9.0
CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF WS-Security endorsing and supporting signature verification does not ensure the selected ds:Signature covers th…
- CVE-2026-54784HIGHCVSS 7.4EG 7.4✓ Fixed in 1.9.12026-06-19
vulnerable: 1.9.0
CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. In version 1.9.0, CoreWCF SPNEGO SecurityContextToken negotiation can expose the proof key recovered from the RSTR when TransportWithMessageCrede…
Check whether CoreWCF.Primitives is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for CoreWCF.Primitives CVEs against the assets you own.
Start Free Scan →