Memory Allocation Vulnerability in bc-csharp by Legion of the Bouncy Castle Inc.
CVE-2026-103603
8.7HIGH
Key Information:
- Status
- Vendor
- CVE Published:
- 2 October 2026
What is CVE-2026-103603?
A memory allocation flaw exists in the HSS/LMS signature code of Legion of the Bouncy Castle Inc.'s bc-csharp library allowing remote, unauthenticated attackers to trigger a denial of service by providing an HSS public key and signature that exceed permissible levels. The lack of checks against the RFC 8554 limit leads to excessive memory consumption during signature verification, possibly causing applications to exhaust system memory and fail with an OutOfMemoryException.
Affected Version(s)
bc-csharp 0 < 2.7.0
References
CVSS V4
Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research.
