CVE-2026-63572
Received Received - Intake

Allocation of Resources Without Limits in Bouncy Castle PKCS#12 Keystore

Vulnerability report for CVE-2026-63572, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: bcorg

Description

Allocation of resources without limits in PKCS#12 keystore loading (Pkcs12Store.Load) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who can supply a PKCS#12 (PFX) file to cause a denial of service through CPU exhaustion via an iteration count close to 2^31 in the file's MacData or in the PBE parameters of an encrypted SafeContents or shrouded key bag, because the counts are taken from the file without an upper bound and the key derivation runs before the MAC or the password can be checked. A zero or negative count is covered by CVE-2026-63575. Pkcs12Utilities.ConvertToDefiniteLength is also affected.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
legion_of_the_bouncy_castle_inc bc-csharp to 2.7.0 (exc)
legion_of_the_bouncy_castle_inc pkcs12utilities to 2.7.0 (exc)
legion_of_the_bouncy_castle_inc bc-csharp 2.7.0
legion_of_the_bouncy_castle_inc bc-csharp 2.7.0-beta.98

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-63572 is a denial-of-service vulnerability in the Bouncy Castle cryptography library (bc-csharp) versions 2.6.2 and earlier. It occurs when loading PKCS#12 keystores, where iteration counts from the file are used without validation. Attackers can craft files with extremely high iteration counts (up to 2^31-1), forcing excessive key derivation loops that consume CPU resources. The vulnerability affects methods like Pkcs12Store.Load and Pkcs12Utilities.ConvertToDefiniteLength.

Detection Guidance

To detect this vulnerability, monitor for unusual CPU usage spikes when processing PKCS#12 files. Check logs for failed PKCS#12 file loads or exceptions related to iteration counts. Use tools like Wireshark to inspect network traffic for large PKCS#12 file transfers. Validate iteration counts in PKCS#12 files using Bouncy Castle's ASN.1 parser before loading.

Impact Analysis

This vulnerability can impact you if your application loads PKCS#12 files from untrusted sources. Attackers can upload malicious files to cause CPU exhaustion, leading to denial-of-service. A single crafted file can consume a thread for up to 15-40 minutes, potentially exhausting system resources if repeatedly exploited. No password is required for the attack.

Compliance Impact

This vulnerability could impact compliance with GDPR and HIPAA by enabling denial-of-service attacks that disrupt availability of cryptographic operations. GDPR requires ensuring availability of personal data processing systems, while HIPAA mandates safeguards against unauthorized access or disruption. Exploiting this flaw could lead to service unavailability, potentially violating these requirements.

Mitigation Strategies

Upgrade to Bouncy Castle C# .NET version 2.7.0 or later. Set iteration count limits via environment variables: Org.BouncyCastle.Pkcs12.MaxIterationCount and Org.BouncyCastle.Pbe.MaxIterationCount. Validate PKCS#12 files from untrusted sources using Org.BouncyCastle.Asn1.Pkcs.Pfx before loading. Block or quarantine suspicious PKCS#12 files with extreme iteration counts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-63572. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart