CVE-2026-103600
Received Received - Intake

Uncontrolled Recursion in Bouncy Castle bc-csharp

Vulnerability report for CVE-2026-103600, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: bcorg

Description

Uncontrolled recursion in the ASN.1 parser (Asn1InputStream, Asn1StreamParser) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote unauthenticated attacker to cause a denial of service via a crafted ASN.1 encoding of deeply nested constructed elements (for example SEQUENCE inside SEQUENCE, in definite-length DER or indefinite-length BER form), because each nesting level is parsed by a further recursive call with no bound on depth. About 2,000 levels (8 KB of DER) are enough to exhaust a 1.5 MB thread stack, the .NET main-thread default on Windows, and raise a StackOverflowException, which .NET cannot catch and which terminates the whole process; on threads with larger stacks, parse time instead grows quadratically with depth (about 9 seconds of CPU for a 64 KB input). Any path that parses untrusted ASN.1 is exposed, including X.509 certificates and CRLs, CMS/PKCS#7, PKCS#8/PKCS#12, OCSP and TLS Certificate messages.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
legion_of_the_bouncy_castle_inc bc-csharp to 2.7.0 (exc)
legion_of_the_bouncy_castle_inc bc_csharp 2.6.2
legion_of_the_bouncy_castle_inc bc_csharp From 2.7.0 (exc)
legion_of_the_bouncy_castle_inc bc_csharp 2.7.0-beta.98

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-674 The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an uncontrolled recursion flaw in the ASN.1 parser of Bouncy Castle's C# library (bc-csharp) versions 2.6.2 and earlier. It allows a remote attacker to cause a denial of service by sending deeply nested ASN.1 encodings, such as SEQUENCE inside SEQUENCE. The parser uses recursive calls without depth limits, leading to stack overflow when parsing around 2,000 levels of nesting. On default .NET stacks, this crashes the entire process with an uncaught StackOverflowException. On larger stacks, it causes excessive CPU usage that grows quadratically with nesting depth.

Detection Guidance

To detect this vulnerability, check if your system uses Bouncy Castle C# versions 2.6.2 or earlier. Inspect ASN.1 parsing code for recursive calls without depth limits. Monitor for crashes or high CPU usage during ASN.1 parsing tasks.

Impact Analysis

If you use affected versions of Bouncy Castle's C# library to parse untrusted ASN.1 data, such as X.509 certificates, CMS/PKCS#7, PKCS#8/12, OCSP, or TLS messages, an attacker could exploit this to crash your application or consume excessive CPU resources. This could disrupt services, cause downtime, or lead to denial of service conditions. Systems processing ASN.1 from untrusted sources are particularly at risk.

Compliance Impact

This vulnerability could impact compliance with GDPR and HIPAA by enabling denial-of-service attacks that disrupt services handling sensitive data. GDPR requires data protection and availability, while HIPAA mandates secure processing of health information. A crash or excessive CPU usage from this flaw could violate availability requirements and potentially expose systems to further attacks.

Mitigation Strategies

Upgrade to Bouncy Castle C# .NET 2.7.0 or later. If upgrading is not possible, implement input validation to limit ASN.1 nesting depth to 64 or less before parsing. Avoid parsing untrusted ASN.1 data until mitigated.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103600. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart