Executive brief
CoreWCF is a library used to build web services in .NET applications. A security flaw in how it verifies digital signatures could allow an attacker to bypass security checks by providing their own signature in a specially crafted message. This could lead to the service accepting unauthorized or tampered data as if it were legitimate.
Technical details
A signature verification vulnerability exists in CoreWCF's WS-Security implementation. The 'WSSecurityOneDotZeroReceiveSecurityHeader' component performs a document-wide 'ds:Signature' lookup rather than restricting the search to the 'wsse:Security' header. An unauthenticated remote attacker can exploit this by placing a SOAP header before the security header, causing the system to verify an attacker-controlled signature instead of the intended one. This is classified as improper verification of cryptographic signatures (CWE-347). The issue is resolved in versions 1.8.1 and 1.9.1 by binding the signature lookup specifically to the Security header subtree.
Affected products
- CoreWCF CoreWCF < 1.8.1, >= 1.9.0 < 1.9.1
Timeline
- 2026-07-08: advisory: NVD publication date
- 2026-07-08: disclosed: GitHub Security Advisory published
- 2026-06-16: patched: Fix committed to repository
References
- https://github.com/CoreWCF/CoreWCF/commit/0589692d4b9a41d21b34ac48281e95f6df7f4ce5
- https://github.com/CoreWCF/CoreWCF/commit/30aef805270976c42477e3f2a05f4e563d86e247
- https://github.com/CoreWCF/CoreWCF/commit/4618f24165ad018ad3ed2636bf8c3bc87d2a3be2
- https://github.com/CoreWCF/CoreWCF/releases/tag/v1.8.1
- https://github.com/CoreWCF/CoreWCF/releases/tag/v1.9.1
- https://github.com/CoreWCF/CoreWCF/security/advisories/GHSA-jc6x-rj79-w4mx