VYPR
Moderate severityNVD Advisory· Published Jun 19, 2026· Updated Jun 19, 2026

CoreWCF: Unix Domain Socket PosixIdentity transport accepts connections that skip the security upgrade

CVE-2026-54776

Description

Impact

A CoreWCF service hosted on Unix Domain Sockets with the PosixIdentity client credential type (UnixDomainSocketBinding with Security.Mode = TransportCredentialOnly and Security.Transport.ClientCredentialType = PosixIdentity) does not require the client to perform the application/unixposix stream upgrade before dispatching messages.

Patches

Fixed in CoreWCF v1.8.1 and v1.9.1

Workarounds

Restrict filesystem access to the UDS socket file using owner/group/mode (e.g. chmod 0660 plus a dedicated group) so that only the POSIX users who are already authorized to invoke the service can connect at all. This makes the missing-upgrade behaviour equivalent to the operating system’s filesystem permissions instead of relying on framing-layer identity checks. Avoid relying on ServiceSecurityContext.PrimaryIdentity for authorization decisions, or back it up with an authentication-required authorization policy that rejects anonymous principals.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
CoreWCF.UnixDomainSocketNuGet
< 1.8.11.8.1
CoreWCF.UnixDomainSocketNuGet
>= 1.9.0, < 1.9.11.9.1

Affected products

1

Patches

Vulnerability mechanics

References

2

News mentions

1