CVE-2026-54780

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, the CoreWCF WS-Security 1.0 receive pipeline validates ds:SignedInfo SignatureMethod against the configured SecurityAlgorithmSuite but does not validate each ds:Reference DigestMethod, allowing a sender to use a rejected digest algorithm such as SHA-1 while the message is still accepted. This issue is fixed in versions 1.8.1 and 1.9.1.
Configurations

No configuration.

History

08 Jul 2026, 23:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-08 23:16

Updated : 2026-07-09 20:16


NVD link : CVE-2026-54780

Mitre link : CVE-2026-54780

CVE.ORG link : CVE-2026-54780


JSON object : View

Products Affected

No product.

CWE
CWE-327

Use of a Broken or Risky Cryptographic Algorithm

CWE-757

Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade')