Vulnerabilities in CoreWCF
14 resultsVexday analysis
CoreWCF apresenta um panorama de risco concentrado e recente: 13 das 14 vulnerabilidades conhecidas foram publicadas nos últimos 90 dias, indicando descobertas ativas e potencialmente ainda não amplamente exploradas. Nenhuma está em ataque ativo (KEV) no momento, embora apenas 1 seja crítica (CVSS); a fraqueza dominante é CWE-347 (falha na validação de certificados), um vetor clássico de comprometimento de confiança. O padrão sugere exposição em fase inicial de divulgação que demanda monitoramento próximo de exploração em campo.
CVE-2026-54772HIGHCoreWCF: Pre-authentication infinite-loop CPU exhaustion in CoreWCF net.tcp / net.pipe / net.uds framing handshakeEPSS 0.8%CVE-2026-54775MEDIUMCoreWCF: Kafka consume pump halts permanently on a Kafka tombstone (null-value record), causing persistent endpoint denial of service.EPSS 0.6%CVE-2024-28252HIGHCoreWCF NetFraming based services can leave connections open when they should be closedEPSS 0.6%CVE-2026-54779MEDIUMCoreWCF: SAML token replay protection is inoperativeEPSS 0.4%CVE-2026-54782CRITICALCoreWCF: Authentication bypass in CoreWCF SAML 1.1 / 2.0 token signature validationEPSS 0.4%CVE-2026-54773MEDIUMCoreWCF: WS-Security signature substitution via document-wide Signature lookupEPSS 0.4%CVE-2026-54784HIGHCoreWCF: SPNEGO SecurityContextToken proof key wrapped without confidentialityEPSS 0.3%CVE-2026-54781HIGHCoreWCF: SAML SubjectConfirmation methods and holder-of-key proof keys are not enforcedEPSS 0.2%CVE-2026-54780LOWCoreWCF: WS-Security Reference DigestMethod Algorithm-Suite BypassEPSS 0.2%CVE-2026-54774HIGHCoreWCF: SamlSerializer skips SignatureValue verification when SAML signing token is not an X.509 certificateEPSS 0.2%CVE-2026-54783HIGHCoreWCF: XML Signature Wrapping in WS-Security endorsing/supporting signature verification allows replay of captured signed messagesEPSS 0.2%CVE-2026-54776MEDIUMCoreWCF: Unix Domain Socket PosixIdentity transport accepts connections that skip the security upgradeEPSS 0.2%CVE-2026-54778MEDIUMCoreWCF: UnixDomainSocket Non-Reentrant POSIX Identity ResolutionEPSS 0.1%CVE-2026-54777MEDIUMCoreWCF NetNamedPipe transport accepts attach to a pre-existing named pipe instanceEPSS 0.1%