Denial of Service Vulnerability in bc-csharp by Legion of the Bouncy Castle Inc.
CVE-2026-63570

7.1HIGH

What is CVE-2026-63570?

A vulnerability exists in the bc-csharp library from Legion of the Bouncy Castle Inc. that allows attackers to trigger a denial of service condition. This occurs when a specially crafted PKCS#12 file, containing circular links in its certificate chain, is provided to an application. The library's inability to effectively manage the recursion of certificates can lead to excessive CPU and memory consumption. The denial of service happens as the library enters an infinite loop while attempting to construct the certificate chain, ultimately resulting in an OutOfMemoryException.

Affected Version(s)

bc-csharp 0 < 2.7.0

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research.
.