8 Total advisories
8 Vulnerabilities
0 Malware
Dependency scanning
Check whether CoreWCF.Primitives is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
HIGH 7.4
CVE-2026-54783
CoreWCF: XML Signature Wrapping in WS-Security endorsing/supporting signature verification allows replay of captured signed messages
MEDIUM 5.9
CVE-2026-54779
CoreWCF: SAML token replay protection is inoperative
HIGH 7.4
CVE-2026-54781
CoreWCF: SAML SubjectConfirmation methods and holder-of-key proof keys are not enforced
LOW 3.7
CVE-2026-54780
CoreWCF: WS-Security Reference DigestMethod Algorithm-Suite Bypass
HIGH 7.4
CVE-2026-54784
CoreWCF: SPNEGO SecurityContextToken proof key wrapped without confidentiality
CRITICAL 10.0
CVE-2026-54782
CoreWCF: Authentication bypass in CoreWCF SAML 1.1 / 2.0 token signature validation
MEDIUM 5.9
CVE-2026-54773
CoreWCF: WS-Security signature substitution via document-wide Signature lookup
HIGH 7.4
CVE-2026-54774
CoreWCF: SamlSerializer skips SignatureValue verification when SAML signing token is not an X.509 certificate
Browse more NuGet advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes