← Back to CVE List
CVE-2026-63572NVD
Vulnerability Summary
Allocation of resources without limits in PKCS#12 keystore loading (Pkcs12Store.Load) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who can supply a PKCS#12 (PFX) file to cause a denial of service through CPU exhaustion via an iteration count close to 2^31 in the file's MacData or in the PBE parameters of an encrypted SafeContents or shrouded key bag, because the counts are taken from the file without an upper bound and the key derivation runs before the MAC or the password can be checked. A zero or negative count is covered by CVE-2026-63575. Pkcs12Utilities.ConvertToDefiniteLength is also affected.
CVSS v4.0 Base Metrics — Score 7.1 (HIGH)
Attack VectorNetwork
Attack ComplexityLow
Attack RequirementsNone
Privileges RequiredNone
User InteractionPassive
Confidentiality (Vulnerable System)None
Integrity (Vulnerable System)None
Availability (Vulnerable System)High
Confidentiality (Subsequent System)None
Integrity (Subsequent System)None
Availability (Subsequent System)None
Affected & Patched Versions
- Legion of the Bouncy Castle Inc. bc-csharp < 2.7.0
- Legion of the Bouncy Castle Inc. bc-csharp 2.7.0
External References
- https://github.com/bcgit/bc-csharp/wiki/CVE-2026-63572
- https://github.com/bcgit/bc-csharp/commit/7c0ed15f9783c9595b1a53f3900136461fd944f4
- https://github.com/bcgit/bc-csharp/commit/c00fc018fca89c077c64dd2a2a2eb00ae7d97241
- https://github.com/bcgit/bc-csharp/commit/54ea0b179ee627027829b44c45d6dd32e575bd67
- https://github.com/bcgit/bc-csharp/commit/34a7c05f719c91c024f285c6b420d3c00f8019dd
- https://github.com/bcgit/bc-csharp/commit/b57165ecb7790ecea08273b219d52d80c12990e4