Denial of Service in ASN.1 Parser for Bouncy Castle .NET Products
CVE-2026-103600
8.7HIGH
Key Information:
- Status
- Vendor
- CVE Published:
- 2 October 2026
What is CVE-2026-103600?
An uncontrolled recursion vulnerability exists in the ASN.1 parser of Bouncy Castle .NET, specifically in the Asn1InputStream and Asn1StreamParser components. This can allow unauthenticated remote attackers to create a denial of service by sending specially crafted ASN.1 encoded data containing deeply nested elements. The recursion without depth limitation can lead to exhaustion of the thread stack, resulting in a StackOverflowException that terminates the process. Any application that processes untrusted ASN.1 data—such as handling X.509 certificates, CMS/PKCS#7 messages, and OCSP responses—is at risk of being affected.
Affected Version(s)
bc-csharp 0 < 2.7.0
