Improper Certificate Validation in Bouncy Castle bc-csharp
CVE-2026-103602

8.2HIGH

What is CVE-2026-103602?

Improper certificate validation in the PkixNameConstraintValidator of Bouncy Castle Inc.'s bc-csharp library prior to version 2.7.0 allows attackers to manipulate certificate validation processes. Specifically, an attacker controlling or able to obtain certificates from a name-constrained intermediate Certificate Authority (CA) can have their certificates incorrectly accepted when validating email addresses, DNS names, or URI hosts. This occurs due to the faulty comparison of names and constraints that do not account for a trailing dot in fully qualified host names, allowing unauthorized access to excluded subtrees for the respective CA.

Affected Version(s)

bc-csharp 0 < 2.7.0

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research.
.