Improper Certificate Validation in Bouncy Castle's bc-csharp Affected by Name Constraints
CVE-2026-63576
Key Information:
- Status
- Vendor
- CVE Published:
- 2 October 2026
What is CVE-2026-63576?
The vulnerability in Bouncy Castle's bc-csharp library arises from improper certificate validation within the PkixNameConstraintValidator component. This issue allows a name-constrained subordinate Certificate Authority (CA) or malicious entities possessing certificates with chosen subjectAltName URIs to bypass crucial name constraints during the certification path validation process. Specifically, the flaw occurs due to the extraction method used for the host, which employs string slicing without adequately isolating the RFC 3986 authority component. This oversight permits discrepancies between the host being checked against constraints and the URI's actual host, potentially leading to security breaches.
Affected Version(s)
bc-csharp 0 < 2.7.0
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
