Resource Exhaustion in bc-csharp Product from Legion of Bouncy Castle Inc.
CVE-2026-63578

7.1HIGH

What is CVE-2026-63578?

A significant vulnerability exists in the bc-csharp library from Legion of Bouncy Castle Inc., where resource allocation is improperly managed during password-based private key decryption. Attackers can exploit this by submitting an encrypted private key, such as a PKCS#8 format or 'ENCRYPTED PRIVATE KEY' in PEM format. This results in denial of service through CPU exhaustion, as the algorithm does not impose limits on the iterative count, which can be set dangerously high, leading to critical performance degradation. This flaw particularly impacts various password-based encryption algorithms including PBKDF2, and has been noted in circumstances involving PKCS#12 files.

Affected Version(s)

bc-csharp 0 < 2.7.0

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research.
.