CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, SamlSerializer skips final SignatureValue verification when a CoreWCF service validates SAML tokens using a non-X.509 signing token, allowing an attacker to reference a non-X.509 SecurityToken key identifier and bypass assertion signature verification. This issue is fixed in versions 1.8.1 and 1.9.1.
References
Configurations
No configuration.
History
08 Jul 2026, 23:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-08 23:16
Updated : 2026-07-10 05:16
NVD link : CVE-2026-54774
Mitre link : CVE-2026-54774
CVE.ORG link : CVE-2026-54774
JSON object : View
Products Affected
No product.
