CVE-2026-103602
Received Received - Intake

PkixNameConstraintValidator Improper Certificate Validation in Bouncy Castle

Vulnerability report for CVE-2026-103602, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: bcorg

Description

Improper certificate validation in PkixNameConstraintValidator in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who controls, or can obtain certificates from, a name-constrained intermediate CA to have certificates accepted during PKIX certification path validation for email addresses, DNS names or URI hosts that lie within excluded subtrees applying to that CA, via an rfc822Name, dNSName or uniformResourceIdentifier name whose host ends with a dot, because names and constraints were compared without first removing the RFC 1034 root-label trailing dot, so a fully qualified host name did not match an excluded subtree for the same host written without the dot.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
legion_of_the_bouncy_castle_inc bc-csharp to 2.7.0 (exc)
legion_of_the_bouncy_castle_inc bc-csharp 2.7.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-295 The product does not validate, or incorrectly validates, a certificate.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves improper certificate validation in the Bouncy Castle C# library. An attacker who controls a name-constrained intermediate CA can issue certificates for email addresses, DNS names, or URI hosts within excluded subtrees by exploiting trailing dots in host names. The library failed to remove trailing dots (RFC 1034 root-label notation) before comparing names against constraints, allowing bypasses of security controls.

Detection Guidance

To detect this vulnerability, check if your system uses Bouncy Castle bc-csharp versions 2.6.2 or earlier. Run commands like 'dotnet list package' or inspect project files for Bouncy Castle references. Verify certificate validation logs for improper handling of trailing dots in DNS names or email addresses.

Impact Analysis

If you use affected versions of Bouncy Castle C# (2.6.2 or earlier), an attacker could bypass name constraints in PKIX certification path validation. This might allow unauthorized certificates to be trusted for domains, email addresses, or URIs that should be excluded, potentially enabling man-in-the-middle attacks or unauthorized access to systems relying on these certificates.

Compliance Impact

This vulnerability could undermine compliance with GDPR, HIPAA, and other regulations requiring secure certificate validation. If certificates are improperly validated, it may lead to unauthorized access to sensitive data, violating confidentiality requirements. Organizations using affected versions must upgrade to mitigate risks to compliance.

Mitigation Strategies

Upgrade to Bouncy Castle bc-csharp version 2.7.0 or later. If upgrading is not immediately possible, implement manual certificate validation checks to ensure trailing dots are properly handled during PKIX path validation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103602. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart