Memory Allocation Vulnerability in bc-csharp by Legion of the Bouncy Castle Inc.
CVE-2026-103603

8.7HIGH

What is CVE-2026-103603?

A memory allocation flaw exists in the HSS/LMS signature code of Legion of the Bouncy Castle Inc.'s bc-csharp library allowing remote, unauthenticated attackers to trigger a denial of service by providing an HSS public key and signature that exceed permissible levels. The lack of checks against the RFC 8554 limit leads to excessive memory consumption during signature verification, possibly causing applications to exhaust system memory and fail with an OutOfMemoryException.

Affected Version(s)

bc-csharp 0 < 2.7.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research.
.