CVE-2026-63576
Received Received - Intake

Improper Certificate Validation in Bouncy Castle bc-csharp

Vulnerability report for CVE-2026-63576, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: bcorg

Description

Improper certificate validation in PkixNameConstraintValidator (ExtractHostFromURL) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a name-constrained subordinate CA, or anyone able to obtain certificates with chosen subjectAltName URIs from such a CA, to bypass permitted or excluded uniformResourceIdentifier name constraints during certification path validation via a URI whose path, query, fragment or userinfo contains characters such as '@' or ':', because the host was extracted by string slicing without first isolating the RFC 3986 authority component, so the host compared against the constraints could differ from the URI's actual host.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
legion_of_the_bouncy_castle_inc bc-csharp to 2.7.0 (exc)
legion_of_the_bouncy_castle_inc bc_csharp to 2.7.0 (exc)
legion_of_the_bouncy_castle_inc bc_csharp 2.7.0
legion_of_the_bouncy_castle_inc bc_csharp 2.7.0-beta.98

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-295 The product does not validate, or incorrectly validates, a certificate.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves improper certificate validation in Bouncy Castle's PkixNameConstraintValidator. It allows a name-constrained subordinate CA or attackers with specific certificates to bypass URI name constraints during certification path validation. The issue occurs because the validator extracts the host from a URI by string slicing without isolating the RFC 3986 authority component first, leading to incorrect host comparisons against permitted or excluded subtrees.

Detection Guidance

Check if your system uses Bouncy Castle's bc-csharp library versions 2.6.2 or earlier, or 2.7.0-beta.98. Inspect applications using PkixCertPathValidator, PkixCertPathBuilder, or PkixNameConstraintValidator for URI name constraint validation. Use System.Uri for manual URI parsing to verify host extraction.

Impact Analysis

If you use affected BC C# .NET versions (2.6.2 and earlier or 2.7.0-beta.98) and rely on URI name constraints for trust, an attacker could craft a certificate that bypasses these constraints. This could allow unauthorized certificates to be trusted, potentially enabling man-in-the-middle attacks or unauthorized access to systems.

Compliance Impact

This vulnerability primarily affects PKIX (X.509) certificate validation, which is foundational for secure communications and identity verification. While it does not directly violate GDPR or HIPAA, it could indirectly impact compliance by undermining trust in certificate-based authentication mechanisms used to protect personal data or health information. Organizations relying on Bouncy Castle's PKIX validation for secure communications may face increased risk of unauthorized access or data breaches if certificates are improperly validated.

Mitigation Strategies

Upgrade to BC C# .NET version 2.7.0 or later. If upgrading is not possible, replace Bouncy Castle's URI parsing with System.Uri for standards-compliant host extraction during validation. Disable URI name constraint checks if not required.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-63576. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart