CVE-2026-54784
HIGHCoreWCF: SPNEGO SecurityContextToken proof key wrapped without confidentiality
Title source: cnaDescription
CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. In version 1.9.0, CoreWCF SPNEGO SecurityContextToken negotiation can expose the proof key recovered from the RSTR when TransportWithMessageCredential with Windows client credentials and session establishment are used, allowing an observer to impersonate the authenticated Windows principal and decrypt or forge WS-SecureConversation traffic. This issue is fixed in version 1.9.1.
References (4)
Core 4
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/CoreWCF/CoreWCF/security/advisories/GHSA-2288-8h3r-cqgg
X_Refsource_Misc x_refsource_misc
https://github.com/CoreWCF/CoreWCF/commit/2afae08b2fa5288428df89e8161116b816cf6b4b
X_Refsource_Misc x_refsource_misc
https://github.com/CoreWCF/CoreWCF/commit/f216aa6929d41dc99cee098b1e69c260ec4c41c7
X_Refsource_Misc x_refsource_misc
https://github.com/CoreWCF/CoreWCF/releases/tag/v1.9.1
Scores
CVSS v3
7.4
EPSS
0.0018
EPSS Percentile
7.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-311
CWE-523
Status
published
Products (1)
CoreWCF/CoreWCF
>= 1.9.0, < 1.9.1
Published
Jul 08, 2026
Tracked Since
Jul 09, 2026