Denial of Service Vulnerability in Bouncy Castle PKCS#12 Keystore
CVE-2026-63572
7.1HIGH
Key Information:
- Status
- Vendor
- CVE Published:
- 2 October 2026
What is CVE-2026-63572?
A vulnerability exists in the Bouncy Castle bc-csharp library, where the PKCS#12 keystore loading function (Pkcs12Store.Load) allows an attacker to supply a malicious PKCS#12 (PFX) file. This can result in denial of service by causing CPU exhaustion, particularly when the iteration counts in the file's MacData or PBE parameters approach 2^31. Due to a lack of upper limits on resource allocation, the key derivation process can be initiated before sufficient checks are performed on the MAC or password, leading to potential service disruption. The vulnerability impacts the conversion utilities as well, including Pkcs12Utilities.ConvertToDefiniteLength.
Affected Version(s)
bc-csharp 0 < 2.7.0
