Denial of Service Vulnerability in Bouncy Castle PKCS#12 Keystore
CVE-2026-63572

7.1HIGH

What is CVE-2026-63572?

A vulnerability exists in the Bouncy Castle bc-csharp library, where the PKCS#12 keystore loading function (Pkcs12Store.Load) allows an attacker to supply a malicious PKCS#12 (PFX) file. This can result in denial of service by causing CPU exhaustion, particularly when the iteration counts in the file's MacData or PBE parameters approach 2^31. Due to a lack of upper limits on resource allocation, the key derivation process can be initiated before sufficient checks are performed on the MAC or password, leading to potential service disruption. The vulnerability impacts the conversion utilities as well, including Pkcs12Utilities.ConvertToDefiniteLength.

Affected Version(s)

bc-csharp 0 < 2.7.0

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.