CVE-2026-63576
Received
Received - Intake
Improper Certificate Validation in Bouncy Castle bc-csharp
Vulnerability report for CVE-2026-63576, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-02
Last updated on: 2026-10-02
Assigner: bcorg
Description
Description
Improper certificate validation in PkixNameConstraintValidator (ExtractHostFromURL) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a name-constrained subordinate CA, or anyone able to obtain certificates with chosen subjectAltName URIs from such a CA, to bypass permitted or excluded uniformResourceIdentifier name constraints during certification path validation via a URI whose path, query, fragment or userinfo contains characters such as '@' or ':', because the host was extracted by string slicing without first isolating the RFC 3986 authority component, so the host compared against the constraints could differ from the URI's actual host.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| legion_of_the_bouncy_castle_inc | bc-csharp | to 2.7.0 (exc) |
| legion_of_the_bouncy_castle_inc | bc_csharp | to 2.7.0 (exc) |
| legion_of_the_bouncy_castle_inc | bc_csharp | 2.7.0 |
| legion_of_the_bouncy_castle_inc | bc_csharp | 2.7.0-beta.98 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-295 | The product does not validate, or incorrectly validates, a certificate. |