Improper Input Validation in Bouncy Castle .NET Library
CVE-2026-63569
9.1CRITICAL
Key Information:
- Status
- Vendor
- CVE Published:
- 2 October 2026
What is CVE-2026-63569?
The Bouncy Castle .NET library (bc-csharp) prior to version 2.7.0 contains a vulnerability due to improper input validation within the DHAgreement.CalculateAgreement method. This flaw allows an on-path attacker to manipulate the Diffie-Hellman key agreement process, potentially resulting in the local party computing a shared value known to the attacker. Furthermore, it may expose the local static private key under certain conditions, especially if the public keys do not undergo necessary range and subgroup membership checks. This vulnerability primarily affects applications that directly utilize the DHAgreement function.
Affected Version(s)
bc-csharp 0 < 2.7.0
References
CVSS V4
Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research.
