<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 20:41:17 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-335328</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-335328</link>
      <description>EUVD-2026-335328</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-335328</guid>
    </item>
    <item>
      <title>fkie_cve-2026-54779</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-54779</link>
      <description>&lt;p&gt;CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF SAML token replay protection is inoperative because DefaultTokenReplayCache.TryAdd does not reject duplicate tokens when DetectReplayedTokens is enabled, allowing a captured token to be reused. This issue is fixed in versions 1.8.1 and 1.9.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF SAML token replay protection is inoperative because DefaultTokenReplayCache.TryAdd does not reject duplicate tokens when DetectReplayedTokens is enabled, allowing a captured token to be reused. This issue is fixed in versions 1.8.1 and 1.9.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-54779</guid>
    </item>
    <item>
      <title>GHSA-9jr3-rj99-8jq3 — CoreWCF: SAML token replay protection is inoperative</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-9jr3-rj99-8jq3</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; NuGet: CoreWCF.Primitives&lt;/p&gt;
&lt;p&gt;### Impact
When enabling DetectReplayedTokens, a token can be replayed and will be detected despite it being reused.&lt;/p&gt;
&lt;p&gt;### Patches
Fixed in CoreWCF v1.8.1 and v1.9.1&lt;/p&gt;
&lt;p&gt;### Workarounds
Provide your own implementation of `ITokenReplayCache` with the correct behavior.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; NuGet: CoreWCF.Primitives&lt;/p&gt;
&lt;p&gt;### Impact
When enabling DetectReplayedTokens, a token can be replayed and will be detected despite it being reused.&lt;/p&gt;
&lt;p&gt;### Patches
Fixed in CoreWCF v1.8.1 and v1.9.1&lt;/p&gt;
&lt;p&gt;### Workarounds
Provide your own implementation of `ITokenReplayCache` with the correct behavior.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-9jr3-rj99-8jq3</guid>
    </item>
  </channel>
</rss>
