Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CoreWCF — Vulnerabilities & Security Advisories 14

All 14 CVE vulnerabilities found in CoreWCF, with AI-generated Chinese analysis, references, and POCs.

This vulnerability aggregation page collects security issues for the .NET CoreWCF product, focusing specifically on Common Weakness Enumeration (CWE) classifications and related vendor advisories. It aggregates known defects including buffer overflows, authentication bypasses, and memory corruption flaws, covering the time range from the initial CoreWCF release through the most recent patch cycle. Users can track security advisories issued by the vendor, analyze the prevalence of specific weakness classes within the product ecosystem, and review the complete vulnerability history for this component. The data highlights how individual flaws have been identified, classified, and remediated over time. By centralizing these records, the page provides a consolidated view of the product’s security posture without requiring manual cross-referencing of disparate sources. The aggregation supports trend analysis for risk assessment, allowing teams to identify recurring patterns in defect types and evaluate the effectiveness of past mitigation efforts.

Vendor: CoreWCF

CVE ID Title CVSS Severity Published
CVE-2026-54782 CoreWCF: Authentication bypass in CoreWCF SAML 1.1 / 2.0 token signature validation CWE-290 10.0 Critical 2026-07-08
CVE-2026-54781 CoreWCF: SAML SubjectConfirmation methods and holder-of-key proof keys are not enforced CWE-287 7.4 High 2026-07-08
CVE-2026-54784 CoreWCF: SPNEGO SecurityContextToken proof key wrapped without confidentiality CWE-311 7.4 High 2026-07-08
CVE-2026-54774 CoreWCF: SamlSerializer skips SignatureValue verification when SAML signing token is not an X.509 certificate CWE-345 7.4 High 2026-07-08
CVE-2026-54783 CoreWCF: XML Signature Wrapping in WS-Security endorsing/supporting signature verification allows replay of captured signed messages CWE-294 7.4 High 2026-07-08
CVE-2026-54780 CoreWCF: WS-Security Reference DigestMethod Algorithm-Suite Bypass CWE-327 3.7 Low 2026-07-08
CVE-2026-54775 CoreWCF: Kafka consume pump halts permanently on a Kafka tombstone (null-value record), causing persistent endpoint denial of service. CWE-248 6.5 Medium 2026-07-08
CVE-2026-54778 CoreWCF: UnixDomainSocket Non-Reentrant POSIX Identity Resolution CWE-362 6.2 Medium 2026-07-08
CVE-2026-54773 CoreWCF: WS-Security signature substitution via document-wide Signature lookup CWE-347 5.9 Medium 2026-07-08
CVE-2026-54779 CoreWCF: SAML token replay protection is inoperative CWE-294 5.9 Medium 2026-07-08
CVE-2026-54772 CoreWCF: Pre-authentication infinite-loop CPU exhaustion in CoreWCF net.tcp / net.pipe / net.uds framing handshake CWE-400 7.5 High 2026-07-08
CVE-2026-54776 CoreWCF: Unix Domain Socket PosixIdentity transport accepts connections that skip the security upgrade CWE-306 4.4 Medium 2026-07-08
CVE-2026-54777 CoreWCF NetNamedPipe transport accepts attach to a pre-existing named pipe instance CWE-367 6.5 Medium 2026-07-08
CVE-2024-28252 CoreWCF NetFraming based services can leave connections open when they should be closed CWE-404 7.5 High 2024-03-15

All 14 known CVE vulnerabilities affecting CoreWCF with full Chinese analysis, references, and POCs where available.