Legion of the Bouncy Castle bc-csharp

21 known vulnerabilities in Legion of the Bouncy Castle bc-csharp, 1 critical, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-63578 CVSS 7.1 high Allocation of resources without limits in password-based private-key decryption (PbeUtilities.GenerateCipherParameters) in Legion of the…
  • CVE-2026-63577 CVSS 8.2 high Improper certificate validation in the directoryName name-constraint check (PkixNameConstraintValidator.WithinDNSubtree) in Legion of the…
  • CVE-2026-63576 CVSS 8.2 high Improper certificate validation in PkixNameConstraintValidator (ExtractHostFromURL) in Legion of the Bouncy Castle Inc. bc-csharp before…
  • CVE-2026-63575 CVSS 7.1 high Loop with unreachable exit condition in the PKCS#12 key derivation (Pkcs12ParametersGenerator) in Legion of the Bouncy Castle Inc…
  • CVE-2026-63574 CVSS 8.7 high Memory allocation with excessive size value in the OpenPGP signature and user attribute subpacket parsers…
  • CVE-2026-63573 CVSS 8.2 high Observable discrepancy in the CMS RSA PKCS#1 v1.5 key-transport unwrap (KeyTransRecipientInformation.UnwrapKey) in Legion of the Bouncy…
  • CVE-2026-63572 CVSS 7.1 high Allocation of resources without limits in PKCS#12 keystore loading (Pkcs12Store.Load) in Legion of the Bouncy Castle Inc. bc-csharp before…
  • CVE-2026-63571 CVSS 8.7 high Improper verification of cryptographic signature in the attribute certificate path validator (PkixAttrCertPathValidator, also used by…
  • CVE-2026-63570 CVSS 7.1 high Loop with unreachable exit condition in Pkcs12Store.GetCertificateChain in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows…
  • CVE-2026-103604 CVSS 8.7 high Inefficient algorithmic complexity in X.509 distinguished name string conversion (X509Name.ToString and IetfUtilities.ValueToString) in…
  • CVE-2026-103603 CVSS 8.7 high Memory allocation with excessive size value in the HSS/LMS signature code (HssPublicKeyParameters, HssSignature) in Legion of the Bouncy…
  • CVE-2026-103602 CVSS 8.2 high Improper certificate validation in PkixNameConstraintValidator in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an…
  • CVE-2026-103601 CVSS 8.2 high Release of unverified plaintext in the CCM (CcmBlockCipher) and DSTU 7624 CCM (KCcmBlockCipher) AEAD modes in Legion of the Bouncy Castle…
  • CVE-2026-103600 CVSS 8.7 high Uncontrolled recursion in the ASN.1 parser (Asn1InputStream, Asn1StreamParser) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0…
  • CVE-2026-63569 CVSS 9.1 critical Improper input validation in DHAgreement.CalculateAgreement (MTI/A0 two-pass Diffie-Hellman) in Legion of the Bouncy Castle Inc. bc-csharp…
  • CVE-2026-63568 CVSS 8.7 high Allocation of resources without limits or throttling in the CMP/CRMF password-based MAC verifier (PKMacBuilder) in Legion of the Bouncy…
  • CVE-2026-63567 CVSS 8.2 high Observable discrepancy in IesEngine.DecryptBlock in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote attacker who…
  • CVE-2026-63566 CVSS 8.7 high Memory allocation with excessive size value in the DTLS handshake reassembly (DtlsReliableHandshake, DtlsReassembler) in Legion of the…
  • CVE-2026-16001 CVSS 8.2 high Exposure of the message authentication key through the encryption keystream in the stream mode of IesEngine (an IesEngine constructed…
  • CVE-2026-16000 CVSS 8.7 high Missing cryptographic step in the DSTU 7624 CCM mode implementation (KCcmBlockCipher) in Legion of the Bouncy Castle Inc. bc-csharp before…
  • CVE-2026-15999 CVSS 8.2 high Improper validation of integrity check value in the AES-CCM implementation (CcmParameters and CcmBlockCipher) in Legion of the Bouncy…