Denial of Service Risk in Bouncy Castle's X.509 Certificate Handling
CVE-2026-103604
8.7HIGH
Key Information:
- Status
- Vendor
- CVE Published:
- 2 October 2026
What is CVE-2026-103604?
An inefficient algorithmic complexity issue in the X.509 distinguished name string conversion within Bouncy Castle's bc-csharp library allows a remote, unauthenticated attacker to exploit the vulnerability. By supplying a certificate or other structured data containing a lengthy attribute value embedded with characters that require escaping, attackers can induce CPU exhaustion on affected systems. The algorithm's performance degrades significantly as it improperly scales with the length of input, leading to potential denial of service when applications attempt to log, display, or validate these names.
Affected Version(s)
bc-csharp 0 < 2.7.0
References
CVSS V4
Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research.
