Improper Input Validation in Bouncy Castle .NET Library
CVE-2026-63569

9.1CRITICAL

What is CVE-2026-63569?

The Bouncy Castle .NET library (bc-csharp) prior to version 2.7.0 contains a vulnerability due to improper input validation within the DHAgreement.CalculateAgreement method. This flaw allows an on-path attacker to manipulate the Diffie-Hellman key agreement process, potentially resulting in the local party computing a shared value known to the attacker. Furthermore, it may expose the local static private key under certain conditions, especially if the public keys do not undergo necessary range and subgroup membership checks. This vulnerability primarily affects applications that directly utilize the DHAgreement function.

Affected Version(s)

bc-csharp 0 < 2.7.0

References

CVSS V4

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research.
.