Memory Allocation Flaw in bc-csharp Product by Legion of the Bouncy Castle Inc.
CVE-2026-63574
8.7HIGH
Key Information:
- Status
- Vendor
- CVE Published:
- 2 October 2026
What is CVE-2026-63574?
An issue has been identified in the bc-csharp library where improper memory allocation occurs within OpenPGP signature and user attribute subpacket parsers. The vulnerability arises due to the handling of excessively large size values in these parsers, allowing a remote, unauthenticated attacker to craft specific OpenPGP public keys, certificates, or signatures. This can lead to denial of service via an OutOfMemoryException, as the library may attempt to allocate buffers up to approximately 2 GB without proper checks against input size. If successfully exploited, this can cause significant disruptions in service.
Affected Version(s)
bc-csharp 0 < 2.7.0
References
CVSS V4
Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research.
