CVE-2026-63575
Received Received - Intake

Loop with Unreachable Exit in Bouncy Castle PKCS#12 Key Derivation

Vulnerability report for CVE-2026-63575, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: bcorg

Description

Loop with unreachable exit condition in the PKCS#12 key derivation (Pkcs12ParametersGenerator) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who can supply a PKCS#12 (PFX) file, or a PKCS#8 encrypted private key that uses a PKCS#12 password-based encryption algorithm, to cause a denial of service through CPU exhaustion via an iteration count of zero or below, because the derivation loop ran until its counter equalled the count, so for such a count it wrapped through about 2^32 iterations before the MAC or the password could be checked. A 75-byte PFX file with a negative MacData iteration count kept Pkcs12Store.Load busy for many minutes.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
bouncy_castle_inc bc-csharp to 2.7.0 (exc)
bouncy_castle_inc bc_csharp to 2.7.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-835 The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves a loop condition error in the PKCS#12 key derivation function of the Bouncy Castle C# library. The loop incorrectly handled iteration counts, causing it to run excessively (up to 2^32 times) for zero or negative counts. This led to CPU exhaustion and denial-of-service conditions when processing maliciously crafted PKCS#12 files or encrypted private keys.

Detection Guidance

To detect this vulnerability, check if your system uses Bouncy Castle C# library versions 2.6.2 or earlier, or 2.7.0-beta.98 pre-release. Inspect PKCS#12 files or PKCS#8 encrypted private keys for negative or zero iteration counts. Monitor CPU usage spikes when processing such files.

Impact Analysis

An attacker could exploit this by providing a specially crafted PKCS#12 file or encrypted private key with a negative iteration count. This would cause applications using the affected Bouncy Castle library to consume excessive CPU resources, leading to performance degradation or complete denial of service.

Compliance Impact

This vulnerability could impact compliance with GDPR and HIPAA by enabling denial-of-service attacks through CPU exhaustion when processing PKCS#12 files. GDPR requires data protection measures against unauthorized access or disruption, while HIPAA mandates safeguards for protected health information availability. The excessive CPU usage could disrupt services handling sensitive data, potentially violating availability requirements in both standards.

Mitigation Strategies

Upgrade to Bouncy Castle C# library version 2.7.0 or later. If upgrading is not possible, manually validate PKCS#12 files and reject those with iteration counts below 1. Avoid processing untrusted PKCS#12 files or PKCS#8 encrypted private keys until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-63575. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart