CVE-2026-63572

Published: Ott 02, 2026 Last Modified: Ott 02, 2026
ExploitDB:
Other exploit source:
Google Dorks:
HIGH 7,1
Source: 91579145-5d7b-4cc5-b925-a0262ff19630
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: passive
Confidentiality: N/A
Integrity: N/A
Availability: N/A

Description

AI Translation Available

Allocation of resources without limits in PKCS#12 keystore loading (Pkcs12Store.Load) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who can supply a PKCS#12 (PFX) file to cause a denial of service through CPU exhaustion via an iteration count close to 2^31 in the file's MacData or in the PBE parameters of an encrypted SafeContents or shrouded key bag, because the counts are taken from the file without an upper bound and the key derivation runs before the MAC or the password can be checked. A zero or negative count is covered by CVE-2026-63575. Pkcs12Utilities.ConvertToDefiniteLength is also affected.

770

Allocation of Resources Without Limits or Throttling

Incomplete
Common Consequences
Security Scopes Affected:
Availability
Potential Impacts:
Dos: Resource Consumption (Cpu) Dos: Resource Consumption (Memory) Dos: Resource Consumption (Other)
Applicable Platforms
All platforms may be affected
View CWE Details
https://github.com/bcgit/bc-csharp/commit/34a7c05f719c91c024f285c6b420d3c00f801…
https://github.com/bcgit/bc-csharp/commit/54ea0b179ee627027829b44c45d6dd32e575b…
https://github.com/bcgit/bc-csharp/commit/7c0ed15f9783c9595b1a53f3900136461fd94…
https://github.com/bcgit/bc-csharp/commit/b57165ecb7790ecea08273b219d52d80c1299…
https://github.com/bcgit/bc-csharp/commit/c00fc018fca89c077c64dd2a2a2eb00ae7d97…
https://github.com/bcgit/bc-csharp/wiki/CVE-2026-63572