---
id: CVE-2026-63574
title: >-
  Memory allocation with excessive size value in the OpenPGP signature and user
  attribute subpacket parsers (SignatureSubpacketsParser.ReadPacket,
  UserAttributeSubpacketsParser.ReadPacket) in Legion of the Bouncy Castle Inc
summary: >-
  Memory allocation with excessive size value in the OpenPGP signature and user
  attribute subpacket parsers (SignatureSubpacketsParser.ReadPacket,
  UserAttributeSubpacketsParser.ReadPacket) in Legion of the Bouncy Castle Inc.
  bc-csharp befo…
severity: high
cvss: 8.7
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'
cwe:
  - CWE-789
vendor: Legion of the Bouncy Castle Inc.
product: BouncyCastle.Cryptography
affected:
  - BouncyCastle.Cryptography < 2.7.0
published: '2026-10-02'
updated: '2026-10-02'
sourceUpdated: '2026-10-02T08:17:02.477'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-63574'
references:
  - url: >-
      https://github.com/bcgit/bc-csharp/commit/986fb4892bb39f292ba0fd82eba11d2cbc503217
    label: 91579145-5d7b-4cc5-b925-a0262ff19630
  - url: >-
      https://github.com/bcgit/bc-csharp/commit/f51dacf4817d9ea10d0a9841f72fac3655c65483
    label: 91579145-5d7b-4cc5-b925-a0262ff19630
  - url: 'https://github.com/bcgit/bc-csharp/wiki/CVE-2026-63574'
    label: 91579145-5d7b-4cc5-b925-a0262ff19630
tags:
  - nvd
  - cve.org
cvssSource: cna
ingestedAt: '2026-10-02T08:14:06.228Z'
---

## Overview

Memory allocation with excessive size value in the OpenPGP signature and user attribute subpacket parsers (SignatureSubpacketsParser.ReadPacket, UserAttributeSubpacketsParser.ReadPacket) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote, unauthenticated attacker who can supply a crafted OpenPGP public key, certificate or signature to cause a denial of service (OutOfMemoryException or memory exhaustion in the parsing process) via a subpacket header using the five-octet length form, because the declared length was used to size the subpacket buffer with no upper bound and without being compared with the size of the enclosing subpacket area or packet, so a few bytes of input could demand an allocation of up to about 2 GB before any subpacket data was read.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
