CVE-2026-103604
Received Received - Intake

Denial of Service in Bouncy Castle C# Library

Vulnerability report for CVE-2026-103604, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: bcorg

Description

Inefficient algorithmic complexity in X.509 distinguished name string conversion (X509Name.ToString and IetfUtilities.ValueToString) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote unauthenticated attacker to cause a denial of service through CPU exhaustion via a certificate, CRL, certification request or other structure whose name contains a long attribute value made up of characters that must be escaped, such as commas, or of leading or trailing spaces, because each escaping backslash was inserted into the buffer being scanned, so the work grew quadratically with the length of the value. Applications are exposed when they convert such a name to a string, for example to log or display it, or compare it with IetfUtilities.RdnAreEqual, as PKIX path validation does for directoryName name constraints.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
legion_of_the_bouncy_castle_inc bc-csharp to 2.7.0 (exc)
bcgit bc-csharp 2.7.0
bcgit bc-csharp to 2.7.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-407 An algorithm in a product has an inefficient worst-case computational complexity that may be detrimental to system performance and can be triggered by an attacker, typically using crafted manipulations that ensure that the worst case is being reached.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a denial-of-service issue in the Bouncy Castle C# library. It occurs when processing X.509 certificates with long attribute values containing special characters like commas or spaces. The library's string conversion functions use an inefficient O(n^2) algorithm that repeatedly inserts escape sequences into a buffer, causing CPU exhaustion for large inputs.

Detection Guidance

Check if your system uses Bouncy Castle C# library versions 2.6.2 or earlier. Inspect logs for high CPU usage during certificate processing or string conversions of X509Name objects. Monitor for slow responses when handling certificates with long attribute values containing special characters.

Impact Analysis

Attackers can craft malicious certificates with extremely long attribute values to trigger excessive CPU usage when the library converts these names to strings. This could slow down or crash applications that process untrusted certificates, such as logging issuer names or validating certificate constraints.

Compliance Impact

This vulnerability primarily causes denial-of-service through CPU exhaustion, which could disrupt system availability. While not directly violating GDPR or HIPAA, prolonged unavailability of systems handling personal or health data could lead to compliance issues related to data access, processing timelines, or security controls. Organizations must ensure systems remain operational to meet regulatory requirements for data protection and availability.

Mitigation Strategies

Upgrade to Bouncy Castle C# library version 2.7.0 or later. If upgrading is not possible, validate certificate attribute lengths before processing and limit certificate sizes from untrusted sources. Avoid logging or displaying certificate names without sanitization.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103604. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart