Memory Allocation Flaw in bc-csharp Product by Legion of the Bouncy Castle Inc.
CVE-2026-63574

8.7HIGH

What is CVE-2026-63574?

An issue has been identified in the bc-csharp library where improper memory allocation occurs within OpenPGP signature and user attribute subpacket parsers. The vulnerability arises due to the handling of excessively large size values in these parsers, allowing a remote, unauthenticated attacker to craft specific OpenPGP public keys, certificates, or signatures. This can lead to denial of service via an OutOfMemoryException, as the library may attempt to allocate buffers up to approximately 2 GB without proper checks against input size. If successfully exploited, this can cause significant disruptions in service.

Affected Version(s)

bc-csharp 0 < 2.7.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research.
.