Improper Certificate Validation in Bouncy Castle's bc-csharp Affected by Name Constraints
CVE-2026-63576

8.2HIGH

What is CVE-2026-63576?

The vulnerability in Bouncy Castle's bc-csharp library arises from improper certificate validation within the PkixNameConstraintValidator component. This issue allows a name-constrained subordinate Certificate Authority (CA) or malicious entities possessing certificates with chosen subjectAltName URIs to bypass crucial name constraints during the certification path validation process. Specifically, the flaw occurs due to the extraction method used for the host, which employs string slicing without adequately isolating the RFC 3986 authority component. This oversight permits discrepancies between the host being checked against constraints and the URI's actual host, potentially leading to security breaches.

Affected Version(s)

bc-csharp 0 < 2.7.0

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research.
.