Buffer Handling Flaw in Bouncy Castle C# Affects Decryption Process
CVE-2026-103601

8.2HIGH

What is CVE-2026-103601?

A vulnerability exists in the Bouncy Castle C# library which improperly handles decryption processes in AEAD modes. Specifically, the issue arises in the CCM and DSTU 7624 CCM modes, where an attacker can exploit this flaw to extract plaintext from failed decryption attempts. By crafting forged messages, an attacker may manipulate the output buffer, allowing the benign plaintext to be revealed before authentication tag checks are performed. This issue underscores the critical importance of secure buffer handling, especially in cryptographic applications where data integrity is paramount.

Affected Version(s)

bc-csharp 0 < 2.7.0

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research.
.