Resource Exhaustion in bc-csharp Product from Legion of Bouncy Castle Inc.
CVE-2026-63578
Key Information:
- Status
- Vendor
- CVE Published:
- 2 October 2026
What is CVE-2026-63578?
A significant vulnerability exists in the bc-csharp library from Legion of Bouncy Castle Inc., where resource allocation is improperly managed during password-based private key decryption. Attackers can exploit this by submitting an encrypted private key, such as a PKCS#8 format or 'ENCRYPTED PRIVATE KEY' in PEM format. This results in denial of service through CPU exhaustion, as the algorithm does not impose limits on the iterative count, which can be set dangerously high, leading to critical performance degradation. This flaw particularly impacts various password-based encryption algorithms including PBKDF2, and has been noted in circumstances involving PKCS#12 files.
Affected Version(s)
bc-csharp 0 < 2.7.0
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
