Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CoreWCF — Vulnerabilities & Security Advisories 14

All 14 CVE vulnerabilities found in CoreWCF, with AI-generated Chinese analysis, references, and POCs.

This page documents Common Weakness Enumerations associated with the CoreWCF product developed by the CoreWCF vendor, focusing on software vulnerabilities and architectural weaknesses. It aggregates a comprehensive list of security defects, ranging from remote code execution and injection flaws to improper access control and insecure configuration issues, covering the period from the initial release through the most recent patch cycles up to the current date. Readers can utilize this resource to track vendor advisories and understand the evolution of specific weakness classes within this technology stack. Additionally, users can look up a product's vulnerability history to identify recurring patterns or critical gaps in the framework’s security model over time. This information is intended for developers, security analysts, and system administrators who need to assess the risk profile of applications relying on CoreWCF. By examining the collected data, stakeholders can make informed decisions regarding mitigation strategies, update schedules, and code review priorities. The page serves as a neutral reference point for evaluating the historical and current security posture of the product without offering recommendations or promotional content. All entries are categorized by severity and affected components to facilitate targeted investigation and remediation efforts. This aggregation aims to provide transparency into the security landscape surrounding CoreWCF, enabling better risk management and compliance reporting for organizations implementing this technology in their production environments.

Vendor: CoreWCF

CVE IDTitleCVSSSeverityPublished
CVE-2026-54782 CoreWCF: Authentication bypass in CoreWCF SAML 1.1 / 2.0 token signature validation CWE-290 10.0 Critical2026-07-08
CVE-2026-54781 CoreWCF: SAML SubjectConfirmation methods and holder-of-key proof keys are not enforced CWE-287 7.4 High2026-07-08
CVE-2026-54784 CoreWCF: SPNEGO SecurityContextToken proof key wrapped without confidentiality CWE-311 7.4 High2026-07-08
CVE-2026-54774 CoreWCF: SamlSerializer skips SignatureValue verification when SAML signing token is not an X.509 certificate CWE-345 7.4 High2026-07-08
CVE-2026-54783 CoreWCF: XML Signature Wrapping in WS-Security endorsing/supporting signature verification allows replay of captured signed messages CWE-294 7.4 High2026-07-08
CVE-2026-54780 CoreWCF: WS-Security Reference DigestMethod Algorithm-Suite Bypass CWE-327 3.7 Low2026-07-08
CVE-2026-54775 CoreWCF: Kafka consume pump halts permanently on a Kafka tombstone (null-value record), causing persistent endpoint denial of service. CWE-248 6.5 Medium2026-07-08
CVE-2026-54778 CoreWCF: UnixDomainSocket Non-Reentrant POSIX Identity Resolution CWE-362 6.2 Medium2026-07-08
CVE-2026-54773 CoreWCF: WS-Security signature substitution via document-wide Signature lookup CWE-347 5.9 Medium2026-07-08
CVE-2026-54779 CoreWCF: SAML token replay protection is inoperative CWE-294 5.9 Medium2026-07-08
CVE-2026-54772 CoreWCF: Pre-authentication infinite-loop CPU exhaustion in CoreWCF net.tcp / net.pipe / net.uds framing handshake CWE-400 7.5 High2026-07-08
CVE-2026-54776 CoreWCF: Unix Domain Socket PosixIdentity transport accepts connections that skip the security upgrade CWE-306 4.4 Medium2026-07-08
CVE-2026-54777 CoreWCF NetNamedPipe transport accepts attach to a pre-existing named pipe instance CWE-367 6.5 Medium2026-07-08
CVE-2024-28252 CoreWCF NetFraming based services can leave connections open when they should be closed CWE-404 7.5 High2024-03-15

All 14 known CVE vulnerabilities affecting CoreWCF with full Chinese analysis, references, and POCs where available.