CVE-2026-63572High· 7.1▾ TwilightAllocation of resources without limits in PKCS#12 keystore loading (Pkcs12Store.Load) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who can supply a PKCS#12 (PFX) file to cause a denial of service through …
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 39.1 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Allocation of resources without limits in PKCS#12 keystore loading (Pkcs12Store.Load) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who can supply a PKCS#12 (PFX) file to cause a denial of service through CPU exhaustion via an iteration count close to 2^31 in the file's MacData or in the PBE parameters of an encrypted SafeContents or shrouded key bag, because the counts are taken from the file without an upper bound and the key derivation runs before the MAC or the password can be checked. A zero or negative count is covered by CVE-2026-63575. Pkcs12Utilities.ConvertToDefiniteLength is also affected.
BouncyCastle.Cryptography < 2.7.0Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-63578High· 7.1Unbounded PBE iteration count when decrypting PKCS#8 private keys
CVE-2026-63575High· 7.1PKCS#12 key derivation loops about 2^32 times on a zero or negative iteration count
CVE-2026-63568High· 8.7Allocation of resources without limits or throttling in the CMP/CRMF password-based MAC verifier (PKMacBuilder) in Legion of the Bouncy Castle Inc
CVE-2026-63571High· 8.7Attribute certificate path validation does not verify the attribute certificate's signature
CVE-2026-63570High· 7.1Pkcs12Store.GetCertificateChain loops forever on cyclic issuer links
CVE-2026-63573High· 8.2Bleichenbacher padding oracle in CMS RSA PKCS#1 v1.5 key-transport unwrap