CVE-2026-54779

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF SAML token replay protection is inoperative because DefaultTokenReplayCache.TryAdd does not reject duplicate tokens when DetectReplayedTokens is enabled, allowing a captured token to be reused. This issue is fixed in versions 1.8.1 and 1.9.1.
Configurations

No configuration.

History

08 Jul 2026, 23:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-08 23:16

Updated : 2026-07-09 16:29


NVD link : CVE-2026-54779

Mitre link : CVE-2026-54779

CVE.ORG link : CVE-2026-54779


JSON object : View

Products Affected

No product.

CWE
CWE-294

Authentication Bypass by Capture-replay

CWE-613

Insufficient Session Expiration