← Back to CVE List
CVE-2026-63578NVD
Vulnerability Summary
Allocation of resources without limits in password-based private-key decryption (PbeUtilities.GenerateCipherParameters) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who can supply an encrypted private key, such as a PKCS#8 EncryptedPrivateKeyInfo or "ENCRYPTED PRIVATE KEY" PEM file, to cause a denial of service through CPU exhaustion via an iteration count close to 2^31, because the count is taken from the unauthenticated algorithm parameters without an upper bound and the key derivation runs before the password or the data can be checked. PKCS#5 PBES1 and PBES2 (PBKDF2), the PKCS#12 PBE algorithms and CMS password recipients (CmsPbeKey) are affected. Loading PKCS#12 files with Pkcs12Store is covered by CVE-2026-63572, and a zero or negative count with the PKCS#12 algorithms by CVE-2026-63575.
CVSS v4.0 Base Metrics — Score 7.1 (HIGH)
Attack VectorNetwork
Attack ComplexityLow
Attack RequirementsNone
Privileges RequiredNone
User InteractionPassive
Confidentiality (Vulnerable System)None
Integrity (Vulnerable System)None
Availability (Vulnerable System)High
Confidentiality (Subsequent System)None
Integrity (Subsequent System)None
Availability (Subsequent System)None
Affected & Patched Versions
- Legion of the Bouncy Castle Inc. bc-csharp < 2.7.0
- Legion of the Bouncy Castle Inc. bc-csharp 2.7.0
External References
- https://github.com/bcgit/bc-csharp/wiki/CVE-2026-63578
- https://github.com/bcgit/bc-csharp/commit/c00fc018fca89c077c64dd2a2a2eb00ae7d97241
- https://github.com/bcgit/bc-csharp/commit/54ea0b179ee627027829b44c45d6dd32e575bd67
- https://github.com/bcgit/bc-csharp/commit/7c0ed15f9783c9595b1a53f3900136461fd944f4
- https://github.com/bcgit/bc-csharp/commit/34a7c05f719c91c024f285c6b420d3c00f8019dd
- https://github.com/bcgit/bc-csharp/commit/b57165ecb7790ecea08273b219d52d80c12990e4