CVE-2026-54774: CoreWCF: SamlSerializer skips SignatureValue verification when SAML signing token is not an X.509 certificate
When a service is configured to validate SAML tokens using a method other than X.509 certificate signing, the final signature verification is skipped.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-54774 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →