CVE-2026-63577
Received Received - Intake

Improper Certificate Validation in Bouncy Castle C# Library

Vulnerability report for CVE-2026-63577, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: bcorg

Description

Improper certificate validation in the directoryName name-constraint check (PkixNameConstraintValidator.WithinDNSubtree) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who controls, or can have certificates issued by, a name-constrained intermediate CA to get certificates accepted by PKIX path validation whose subject distinguished name, or a directoryName subjectAltName, lies outside the CA's permitted subtrees, via a name that places other RDNs ahead of a copy of the permitted RDN sequence, because the check looks for the constraint's first RDN anywhere in the name and compares the remaining RDNs from that position, instead of requiring the constraint to be an initial prefix of the name as RFC 5280 sections 4.2.1.10 and 7.1 require.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
bouncy_castle_inc bc_csharp to 2.7.0 (exc)
bouncy_castle_inc bc_csharp 2.7.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-295 The product does not validate, or incorrectly validates, a certificate.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves improper certificate validation in the Bouncy Castle library's PkixNameConstraintValidator. It allows an attacker who controls a name-constrained intermediate CA to issue certificates with subject names outside the permitted namespace. The issue occurs because the validator checks if a permitted directoryName sequence appears anywhere in the certificate's subject name, rather than requiring it to match from the start as per RFC 5280 standards.

Detection Guidance

To detect this vulnerability, check if your system uses Bouncy Castle C# .NET versions 2.6.2 or earlier, or 2.7.0-beta.98 pre-release. Verify if your application validates certificate paths using PkixCertPathValidator or PkixCertPathBuilder with intermediate CAs that have directoryName constraints. Manually inspect certificates for subject names or directoryName subjectAltNames that may contain permitted RDN sequences not at the start of the name.

Impact Analysis

Applications using BC C# .NET versions 2.6.2 or earlier that validate certificate paths with PkixCertPathValidator or PkixCertPathBuilder could accept invalid certificates. This may allow man-in-the-middle attacks or unauthorized access if an attacker exploits the flaw to issue rogue certificates.

Compliance Impact

This vulnerability could undermine compliance with standards requiring secure certificate validation, such as GDPR's data protection measures or HIPAA's encryption requirements. Invalid certificates may lead to unauthorized data access or breaches, violating regulatory obligations.

Mitigation Strategies

Upgrade to Bouncy Castle C# .NET version 2.7.0 or later to fix the improper certificate validation. If upgrading is not immediately possible, manually verify that end-entity certificates' subject names and directoryName subjectAltNames begin with the full permitted RDN sequence before trusting them.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-63577. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart