Improper Certificate Validation in Bouncy Castle’s bc-csharp Product
CVE-2026-63577
Key Information:
- Status
- Vendor
- CVE Published:
- 2 October 2026
What is CVE-2026-63577?
The bc-csharp library from Legion of the Bouncy Castle Inc. contains an improper certificate validation flaw. Specifically, the name-constraint check, 'PkixNameConstraintValidator.WithinDNSubtree', does not enforce correct validation protocols as stipulated in RFC 5280. This vulnerability allows attackers, who control or can have certificates issued by a name-constrained intermediate CA, to have their certificates erroneously accepted by the PKIX path validation process. They can exploit this flaw by using a subject distinguished name or directoryName subjectAltName that falls outside the permitted subtrees, facilitated by arranging RDNs in a manner that undermines the intended constraints.
Affected Version(s)
bc-csharp 0 < 2.7.0
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
