Description
CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF WS-Security endorsing and supporting signature verification does not ensure the selected ds:Signature covers the expected Security header target, allowing an attacker with one captured signed SOAP envelope to replay arbitrary service operations as the victim principal. This issue is fixed in versions 1.8.1 and 1.9.1.
References (6)
Core 6
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/CoreWCF/CoreWCF/security/advisories/GHSA-gqv6-pwcg-87r8
X_Refsource_Misc x_refsource_misc
https://github.com/CoreWCF/CoreWCF/commit/0589692d4b9a41d21b34ac48281e95f6df7f4ce5
X_Refsource_Misc x_refsource_misc
https://github.com/CoreWCF/CoreWCF/commit/30aef805270976c42477e3f2a05f4e563d86e247
X_Refsource_Misc x_refsource_misc
https://github.com/CoreWCF/CoreWCF/commit/4618f24165ad018ad3ed2636bf8c3bc87d2a3be2
X_Refsource_Misc x_refsource_misc
https://github.com/CoreWCF/CoreWCF/releases/tag/v1.8.1
X_Refsource_Misc x_refsource_misc
https://github.com/CoreWCF/CoreWCF/releases/tag/v1.9.1
Scores
CVSS v3
7.4
EPSS
0.0014
EPSS Percentile
4.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-294
CWE-345
CWE-347
Status
published
Products (2)
CoreWCF/CoreWCF
< 1.8.1
CoreWCF/CoreWCF
>= 1.9.0, < 1.9.1
Published
Jul 08, 2026
Tracked Since
Jul 09, 2026