Denial of Service Vulnerability in Bouncy Castle's PKCS#12 Key Derivation Function
CVE-2026-63575

7.1HIGH

What is CVE-2026-63575?

In the Bouncy Castle library's PKCS#12 key derivation process, a vulnerability exists due to a loop with an unreachable exit condition in the Pkcs12ParametersGenerator class. An attacker can exploit this by supplying a specially crafted PKCS#12 (PFX) file or PKCS#8 encrypted private key utilizing a password-based encryption algorithm. This results in CPU exhaustion as the algorithm runs an excessive number of iterations due to a negative iteration count. A small PFX file, for example, could cause system performance degradation by keeping the Pkcs12Store.Load function running for prolonged periods, potentially leading to denial of service.

Affected Version(s)

bc-csharp 0 < 2.7.0

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Paweł Łukasik (https://github.com/pawlos)
.