CVE-2026-63570
Received Received - Intake

Loop in Certificate Chain Building in Bouncy Castle

Vulnerability report for CVE-2026-63570, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: bcorg

Description

Loop with unreachable exit condition in Pkcs12Store.GetCertificateChain in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who can supply a crafted PKCS#12 file to an application that loads it and requests a key entry's certificate chain to cause a denial of service, in which the call never returns and consumes CPU and memory until an OutOfMemoryException, via certificates whose issuer links form a cycle, for example two certificates whose AuthorityKeyIdentifier extensions each identify the other's public key. This happens because the chain-building loop stops only when no issuer is found or a certificate links to itself, and keeps no record of certificates already visited. The key-identifier links are followed without checking signatures.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
legion_of_the_bouncy_castle_inc bc-csharp to 2.7.0 (exc)
legion_of_the_bouncy_castle_inc bc-csharp 2.7.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-835 The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an infinite loop issue in the Bouncy Castle library's Pkcs12Store.GetCertificateChain method. When processing PKCS#12 files with certificate chains that contain circular references, such as two certificates referencing each other as issuers, the method fails to detect the loop and continues processing indefinitely. This leads to excessive CPU and memory consumption until an OutOfMemoryException occurs, causing a denial of service.

Detection Guidance

To detect this vulnerability, monitor for applications using Bouncy Castle's bc-csharp library versions 2.6.2 or earlier that process PKCS#12 files and call GetCertificateChain. Check for signs of infinite loops such as high CPU or memory usage when loading certificates. Review logs for OutOfMemoryException errors during certificate chain processing.

Impact Analysis

If you use an affected version of the Bouncy Castle library in an application that loads PKCS#12 files from untrusted sources and requests certificate chains, an attacker could craft a malicious file to trigger this vulnerability. This would cause your application to hang, consume excessive system resources, and potentially crash due to an OutOfMemoryException, disrupting service availability.

Compliance Impact

This vulnerability could impact compliance by causing service disruptions due to denial of service, potentially violating availability requirements in GDPR and HIPAA. GDPR emphasizes data availability and security, while HIPAA requires safeguards to ensure access to protected health information. An application crash or hang could lead to unauthorized access or data loss, triggering compliance violations.

Mitigation Strategies
  • Upgrade to Bouncy Castle bc-csharp version 2.7.0 or later to fix the infinite loop issue in Pkcs12Store.GetCertificateChain.
  • If upgrading is not possible, avoid calling GetCertificateChain on PKCS#12 keystores loaded from untrusted sources.
  • Implement input validation to reject PKCS#12 files with suspicious certificate chains that may form cycles.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-63570. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart