---
id: CVE-2026-63577
title: >-
  Improper certificate validation in the directoryName name-constraint check
  (PkixNameConstraintValidator.WithinDNSubtree) in Legion of the Bouncy Castle
  Inc
summary: >-
  Improper certificate validation in the directoryName name-constraint check
  (PkixNameConstraintValidator.WithinDNSubtree) in Legion of the Bouncy Castle
  Inc. bc-csharp before 2.7.0 allows an attacker who controls, or can have
  certificates…
severity: high
cvss: 8.2
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'
cwe:
  - CWE-295
vendor: Legion of the Bouncy Castle Inc.
product: BouncyCastle.Cryptography
affected:
  - BouncyCastle.Cryptography < 2.7.0
published: '2026-10-02'
updated: '2026-10-02'
sourceUpdated: '2026-10-02T08:17:02.937'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-63577'
references:
  - url: >-
      https://github.com/bcgit/bc-csharp/commit/606e9153b97a265c70ca8293d21ec859344d7de8
    label: 91579145-5d7b-4cc5-b925-a0262ff19630
  - url: >-
      https://github.com/bcgit/bc-csharp/commit/75c3c576602886180ed92a63c89419e3bd63b392
    label: 91579145-5d7b-4cc5-b925-a0262ff19630
  - url: 'https://github.com/bcgit/bc-csharp/wiki/CVE-2026-63577'
    label: 91579145-5d7b-4cc5-b925-a0262ff19630
tags:
  - nvd
  - cve.org
cvssSource: cna
ingestedAt: '2026-10-02T08:14:06.227Z'
---

## Overview

Improper certificate validation in the directoryName name-constraint check (PkixNameConstraintValidator.WithinDNSubtree) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who controls, or can have certificates issued by, a name-constrained intermediate CA to get certificates accepted by PKIX path validation whose subject distinguished name, or a directoryName subjectAltName, lies outside the CA's permitted subtrees, via a name that places other RDNs ahead of a copy of the permitted RDN sequence, because the check looks for the constraint's first RDN anywhere in the name and compares the remaining RDNs from that position, instead of requiring the constraint to be an initial prefix of the name as RFC 5280 sections 4.2.1.10 and 7.1 require.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
