CVE-2026-63572
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Summary
Allocation of resources without limits in PKCS#12 keystore loading (Pkcs12Store.Load) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who can supply a PKCS#12 (PFX) file to cause a denial of service through CPU exhaustion via an iteration count close to 2^31 in the file's MacData or in the PBE parameters of an encrypted SafeContents or shrouded key bag, because the counts are taken from the file without an upper bound and the key derivation runs before the MAC or the password can be checked. A zero or negative count is covered by CVE-2026-63575. Pkcs12Utilities.ConvertToDefiniteLength is also affected.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Legion of the Bouncy Castle Inc. | bc-csharp | 0 < 2.7.0 | affected |
Weaknesses
- CWE-770: CWE-770 Allocation of Resources Without Limits or Throttling
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: partial
References
- https://github.com/bcgit/bc-csharp/wiki/CVE-2026-63572
- https://github.com/bcgit/bc-csharp/commit/7c0ed15f9783c9595b1a53f3900136461fd944f4
- https://github.com/bcgit/bc-csharp/commit/c00fc018fca89c077c64dd2a2a2eb00ae7d97241
- https://github.com/bcgit/bc-csharp/commit/54ea0b179ee627027829b44c45d6dd32e575bd67
- https://github.com/bcgit/bc-csharp/commit/34a7c05f719c91c024f285c6b420d3c00f8019dd
- https://github.com/bcgit/bc-csharp/commit/b57165ecb7790ecea08273b219d52d80c12990e4
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.