Denial of Service Risk in Bouncy Castle's X.509 Certificate Handling
CVE-2026-103604

8.7HIGH

What is CVE-2026-103604?

An inefficient algorithmic complexity issue in the X.509 distinguished name string conversion within Bouncy Castle's bc-csharp library allows a remote, unauthenticated attacker to exploit the vulnerability. By supplying a certificate or other structured data containing a lengthy attribute value embedded with characters that require escaping, attackers can induce CPU exhaustion on affected systems. The algorithm's performance degrades significantly as it improperly scales with the length of input, leading to potential denial of service when applications attempt to log, display, or validate these names.

Affected Version(s)

bc-csharp 0 < 2.7.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research.
.