Improper Cryptographic Signature Validation in Bouncy Castle's C# Implementation
CVE-2026-63571

8.7HIGH

What is CVE-2026-63571?

A critical flaw exists in the Bouncy Castle C# library prior to version 2.7.0, where the PkixAttrCertPathValidator does not properly verify the cryptographic signature of attribute certificates. This oversight can potentially allow a remote attacker to exploit the system by presenting a forged X.509 attribute certificate that falsely claims to originate from a trusted authority. The vulnerability arises from the inability to verify the certificate's signature against the issuer's public key during validation, leading applications to erroneously accept invalid certificates and grant inappropriate roles or privileges.

Affected Version(s)

bc-csharp 0 < 2.7.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research.
.