Executive brief
CoreWCF, a tool used to run Windows Communication Foundation services on modern .NET platforms, contains a security flaw in how it verifies digital signatures for SAML identity tokens. When a service is configured to use certain types of security keys, an attacker can bypass the signature check by providing a forged token. This could allow an unauthorized user to impersonate others or gain elevated access to the service and its data.
Technical details
A vulnerability exists in CoreWCF's SamlSerializer.ReadToken method where signature verification logic branches based on the token type. While X509SecurityTokens undergo full XML-DSig verification, other token types (such as symmetric proof-keys used in WS-Trust scenarios) only trigger a digest-only verification of the SignedInfo block. This root cause allows an attacker to author a SAML assertion, compute the Reference DigestValue, and provide an arbitrary SignatureValue that is never cryptographically validated against a key. The issue is reachable when using WSSecurityTokenSerializer with an out-of-band issuer-token resolver containing non-X.509 tokens. The vulnerability is fixed in versions 1.8.1 and 1.9.1 by ensuring full key-based verification for all supported security key types.
Affected products
- CoreWCF CoreWCF < 1.8.1, >= 1.9.0 < 1.9.1
Timeline
- 2026-07-08: disclosed
- 2026-07-08: advisory
References
- https://github.com/CoreWCF/CoreWCF/commit/65d09022749854ba943e376aefb958dec05b00d8
- https://github.com/CoreWCF/CoreWCF/commit/b914495ce63c44924664643b60a262e7595081a4
- https://github.com/CoreWCF/CoreWCF/commit/e7454132876ecc7e2cf80e541a44376eeb54979b
- https://github.com/CoreWCF/CoreWCF/releases/tag/v1.8.1
- https://github.com/CoreWCF/CoreWCF/releases/tag/v1.9.1
- https://github.com/CoreWCF/CoreWCF/security/advisories/GHSA-rpj7-hr7h-w6p9