---
id: CVE-2026-103604
title: >-
  Inefficient algorithmic complexity in X.509 distinguished name string
  conversion (X509Name.ToString and IetfUtilities.ValueToString) in Legion of
  the Bouncy Castle Inc
summary: >-
  Inefficient algorithmic complexity in X.509 distinguished name string
  conversion (X509Name.ToString and IetfUtilities.ValueToString) in Legion of
  the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote unauthenticated
  attacker to c…
severity: high
cvss: 8.7
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'
cwe:
  - CWE-407
vendor: Legion of the Bouncy Castle Inc.
product: BouncyCastle.Cryptography
affected:
  - BouncyCastle.Cryptography < 2.7.0
published: '2026-10-02'
updated: '2026-10-02'
sourceUpdated: '2026-10-02T08:17:00.980'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-103604'
references:
  - url: >-
      https://github.com/bcgit/bc-csharp/commit/bd03e38bbb49db5be33f4463fc40997400c545cc
    label: 91579145-5d7b-4cc5-b925-a0262ff19630
  - url: 'https://github.com/bcgit/bc-csharp/wiki/CVE-2026-103604'
    label: 91579145-5d7b-4cc5-b925-a0262ff19630
tags:
  - nvd
  - cve.org
cvssSource: cna
ingestedAt: '2026-10-02T08:14:06.225Z'
---

## Overview

Inefficient algorithmic complexity in X.509 distinguished name string conversion (X509Name.ToString and IetfUtilities.ValueToString) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote unauthenticated attacker to cause a denial of service through CPU exhaustion via a certificate, CRL, certification request or other structure whose name contains a long attribute value made up of characters that must be escaped, such as commas, or of leading or trailing spaces, because each escaping backslash was inserted into the buffer being scanned, so the work grew quadratically with the length of the value. Applications are exposed when they convert such a name to a string, for example to log or display it, or compare it with IetfUtilities.RdnAreEqual, as PKIX path validation does for directoryName name constraints.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
