Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 2

Количество 2

nvd логотип

CVE-2026-54782

около 1 месяца назад

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF SAML 1.1 and SAML 2.0 token validation does not correctly resolve the issuer signing key or require signed tokens when IdentityConfiguration is used with federated bindings, allowing an unauthenticated remote attacker to impersonate any principal the trusted STS could issue. This issue is fixed in versions 1.8.1 and 1.9.1.

CVSS3: 10
EPSS: Низкий
github логотип

GHSA-xjr9-gg9q-jx3v

около 2 месяцев назад

CoreWCF: Authentication bypass in CoreWCF SAML 1.1 / 2.0 token signature validation

CVSS3: 10
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-54782

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF SAML 1.1 and SAML 2.0 token validation does not correctly resolve the issuer signing key or require signed tokens when IdentityConfiguration is used with federated bindings, allowing an unauthenticated remote attacker to impersonate any principal the trusted STS could issue. This issue is fixed in versions 1.8.1 and 1.9.1.

CVSS3: 10
0%
Низкий
около 1 месяца назад
github логотип
GHSA-xjr9-gg9q-jx3v

CoreWCF: Authentication bypass in CoreWCF SAML 1.1 / 2.0 token signature validation

CVSS3: 10
0%
Низкий
около 2 месяцев назад

Уязвимостей на страницу