Denial of Service Vulnerability in Bouncy Castle's PKCS#12 Key Derivation Function
CVE-2026-63575
7.1HIGH
Key Information:
- Status
- Vendor
- CVE Published:
- 2 October 2026
What is CVE-2026-63575?
In the Bouncy Castle library's PKCS#12 key derivation process, a vulnerability exists due to a loop with an unreachable exit condition in the Pkcs12ParametersGenerator class. An attacker can exploit this by supplying a specially crafted PKCS#12 (PFX) file or PKCS#8 encrypted private key utilizing a password-based encryption algorithm. This results in CPU exhaustion as the algorithm runs an excessive number of iterations due to a negative iteration count. A small PFX file, for example, could cause system performance degradation by keeping the Pkcs12Store.Load function running for prolonged periods, potentially leading to denial of service.
Affected Version(s)
bc-csharp 0 < 2.7.0
References
CVSS V4
Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Paweł Łukasik (https://github.com/pawlos)
