CVE-2026-63578
Received Received - Intake

Resource Exhaustion in Bouncy Castle PKCS#8 Decryption

Vulnerability report for CVE-2026-63578, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: bcorg

Description

Allocation of resources without limits in password-based private-key decryption (PbeUtilities.GenerateCipherParameters) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who can supply an encrypted private key, such as a PKCS#8 EncryptedPrivateKeyInfo or "ENCRYPTED PRIVATE KEY" PEM file, to cause a denial of service through CPU exhaustion via an iteration count close to 2^31, because the count is taken from the unauthenticated algorithm parameters without an upper bound and the key derivation runs before the password or the data can be checked. PKCS#5 PBES1 and PBES2 (PBKDF2), the PKCS#12 PBE algorithms and CMS password recipients (CmsPbeKey) are affected. Loading PKCS#12 files with Pkcs12Store is covered by CVE-2026-63572, and a zero or negative count with the PKCS#12 algorithms by CVE-2026-63575.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
bouncy_castle bc-csharp to 2.7.0 (exc)
bouncy_castle bc-csharp From 2.7.0 (exc)
bouncy_castle bc-csharp to 2.6.2 (exc)
bouncy_castle bc-csharp From 2.7.0-beta.98 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves a flaw in the Bouncy Castle cryptographic library for .NET (bc-csharp) versions 2.6.2 and earlier. It allows an attacker to cause a denial of service by supplying an encrypted private key with an extremely high iteration count (close to 2^31) in the key derivation process. The iteration count is read from unprotected algorithm parameters without an upper bound, forcing the system to perform excessive computations during decryption.

Detection Guidance

To detect this vulnerability, check if your system uses Bouncy Castle C# .NET versions 2.6.2 or earlier, or 2.7.0-beta.98. Inspect applications that decrypt password-protected private keys, especially those handling PKCS#8 EncryptedPrivateKeyInfo or PKCS#12 files. Monitor for unusual CPU usage spikes during key decryption operations.

Impact Analysis

If you use applications that decrypt password-protected private keys from untrusted sources using Bouncy Castle's bc-csharp library, an attacker could exploit this to consume excessive CPU resources. This may lead to system slowdowns, unresponsiveness, or complete denial of service. Applications processing PKCS#8 EncryptedPrivateKeyInfo or PKCS#12 files are particularly at risk.

Compliance Impact

This vulnerability could impact compliance by enabling denial-of-service attacks that disrupt system availability. GDPR requires ensuring the availability of processing systems, while HIPAA mandates safeguards against unauthorized access or disruption. Exploits could violate these requirements by degrading or denying service, potentially leading to non-compliance.

Mitigation Strategies

Upgrade to Bouncy Castle C# .NET 2.7.0 or later to enforce iteration count limits. If immediate upgrade is not possible, validate and restrict iteration counts before passing keys to Bouncy Castle libraries. Avoid processing untrusted PKCS#8 or PKCS#12 files until mitigation is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-63578. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart