Denial of Service Risk in Bouncy Castle's C# Library
CVE-2026-63566
8.7HIGH
Key Information:
- Status
- Vendor
- CVE Published:
- 2 October 2026
What is CVE-2026-63566?
A vulnerability in the Bouncy Castle C# library allows a remote unauthenticated DTLS peer to exploit excessive memory allocation during the handshake process, potentially leading to service disruption. This occurs because the library insufficiently validates the size of incoming handshake message fragments, resulting in excessive memory consumption of nearly 16 MB per fragment, multiplied by multiple pending messages. This issue can affect both DTLS servers and clients, necessitating immediate attention from users of the library.
Affected Version(s)
bc-csharp 0 < 2.7.0
References
CVSS V4
Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research.
