Improper Certificate Validation in Bouncy Castle bc-csharp
CVE-2026-103602
8.2HIGH
Key Information:
- Status
- Vendor
- CVE Published:
- 2 October 2026
What is CVE-2026-103602?
Improper certificate validation in the PkixNameConstraintValidator of Bouncy Castle Inc.'s bc-csharp library prior to version 2.7.0 allows attackers to manipulate certificate validation processes. Specifically, an attacker controlling or able to obtain certificates from a name-constrained intermediate Certificate Authority (CA) can have their certificates incorrectly accepted when validating email addresses, DNS names, or URI hosts. This occurs due to the faulty comparison of names and constraints that do not account for a trailing dot in fully qualified host names, allowing unauthorized access to excluded subtrees for the respective CA.
Affected Version(s)
bc-csharp 0 < 2.7.0
References
CVSS V4
Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research.
