CVE-2026-103601
Received Received - Intake

Authentication Tag Bypass in Bouncy Castle bc-csharp

Vulnerability report for CVE-2026-103601, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: bcorg

Description

Release of unverified plaintext in the CCM (CcmBlockCipher) and DSTU 7624 CCM (KCcmBlockCipher) AEAD modes in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote attacker to obtain decryptions of ciphertexts of their choosing via forged messages sent to an application that lets the output buffer of a failed decryption be observed, for example through buffer reuse or logging, because decryption wrote the recovered plaintext into the caller-supplied output buffer before checking the authentication tag and left it there when the check failed. Only decryption into a caller-supplied buffer is affected; methods that return a newly allocated array are not.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
legion_of_the_bouncy_castle_inc bc-csharp to 2.7.0 (exc)
bouncy_castle bc_csharp 2.7.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-354 The product does not validate or incorrectly validates the integrity check values or "checksums" of a message. This may prevent it from detecting if the data has been modified or corrupted in transmission.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves the Bouncy Castle C# library's CCM and DSTU 7624 CCM decryption modes. When decrypting ciphertext, the library writes recovered plaintext into a caller-supplied output buffer before verifying the authentication tag. If the tag check fails, the plaintext remains exposed in the buffer, allowing attackers to obtain decrypted data by sending forged messages. The issue affects versions 2.6.2 and earlier, as well as 2.7.0-beta.98.

Detection Guidance

To detect this vulnerability, check if your system uses BC C# .NET versions 2.6.2 or earlier, or 2.7.0-beta.98. Inspect applications using CCM or KCcmBlockCipher modes for decryption into caller-supplied buffers. Look for failed decryptions where plaintext remains in output buffers or logs.

Impact Analysis

Attackers can exploit this to decrypt ciphertexts of their choosing without knowing the encryption key. Applications using affected versions that decrypt untrusted messages into caller-supplied buffers may expose sensitive data through buffer reuse, logging, or other means. The vulnerability turns decryption into an unauthenticated CTR decryption oracle, risking data confidentiality.

Compliance Impact

This vulnerability could lead to unauthorized decryption of sensitive data, violating confidentiality requirements under GDPR and HIPAA. Exposure of plaintext during failed decryption attempts may result in non-compliance with data protection principles, potentially leading to legal penalties or data breach notifications.

Mitigation Strategies

Upgrade to BC C# .NET 2.7.0 or later. If immediate upgrade is not possible, decrypt CCM and KCCM messages into a dedicated buffer and manually clear it if decryption fails. Avoid using caller-supplied buffers for decryption output.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103601. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart