Insufficient Verification of Data Authenticity Affecting corewcf.primitives package, versions [1.0.0-preview1,1.8.1)[1.9.0, 1.9.1)


Severity

Recommended
0.0
critical
0
10

CVSS assessment by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DOTNET-COREWCFPRIMITIVES-17391911
  • published21 Jun 2026
  • disclosed19 Jun 2026
  • creditUnknown

Introduced: 19 Jun 2026

NewCVE-2026-54781  (opens in a new tab)
CWE-287  (opens in a new tab)
CWE-345  (opens in a new tab)

How to fix?

Upgrade CoreWCF.Primitives to version 1.8.1, 1.9.1 or higher.

Overview

CoreWCF.Primitives is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. The goal of this project is to enable existing WCF services to move to .NET Core.

Affected versions of this package are vulnerable to Insufficient Verification of Data Authenticity through the ValidateToken path in SamlSecurityTokenHandler. An attacker can get identity claims accepted without proving possession of the bound key by sending a SAML assertion with an unrecognized SubjectConfirmationMethod URI or a holder-of-key subject that omits SubjectConfirmationData KeyInfo. The relying party then receives claims that were not properly bound to the sender, allowing unauthorized authentication as the asserted subject.

CVSS Base Scores

version 4.0
version 3.1