๐Ÿ” CVE Alert

CVE-2026-103602

UNKNOWN 0.0

Name constraints bypass via trailing dot in rfc822Name, dNSName and URI hosts

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Improper certificate validation in PkixNameConstraintValidator in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who controls, or can obtain certificates from, a name-constrained intermediate CA to have certificates accepted during PKIX certification path validation for email addresses, DNS names or URI hosts that lie within excluded subtrees applying to that CA, via an rfc822Name, dNSName or uniformResourceIdentifier name whose host ends with a dot, because names and constraints were compared without first removing the RFC 1034 root-label trailing dot, so a fully qualified host name did not match an excluded subtree for the same host written without the dot.

CWE CWE-295
Vendor legion of the bouncy castle inc.
Product bc-csharp
Published Oct 2, 2026
Stay Ahead of the Next One

Get instant alerts for legion of the bouncy castle inc. bc-csharp

Be the first to know when new unknown vulnerabilities affecting legion of the bouncy castle inc. bc-csharp are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Legion of the Bouncy Castle Inc. / bc-csharp
0 < 2.7.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/bcgit/bc-csharp/wiki/CVE-2026-103602 github.com: https://github.com/bcgit/bc-csharp/commit/f196a22bbf7765cc19b0c4f4645c74ea7ad35e09 github.com: https://github.com/bcgit/bc-csharp/commit/be276e057775a6a674a62e9d9a2583b229978f73 github.com: https://github.com/bcgit/bc-csharp/commit/75c3c576602886180ed92a63c89419e3bd63b392

Credits

Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research.