๐Ÿ” CVE Alert

CVE-2026-103603

UNKNOWN 0.0

Unbounded HSS public key level count allows huge array allocation during signature verification

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Memory allocation with excessive size value in the HSS/LMS signature code (HssPublicKeyParameters, HssSignature) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote unauthenticated attacker who can supply both an HSS public key and a signature to cause a denial of service through memory exhaustion via a public key encoding with an excessive level count, because the level count L read when parsing an HSS public key was not checked against the RFC 8554 maximum of 8, and signature parsing then allocated an array of L - 1 entries before reading any further signature data. A single verification can commit up to about 17 GB of memory or fail with an OutOfMemoryException.

CWE CWE-789
Vendor legion of the bouncy castle inc.
Product bc-csharp
Published Oct 2, 2026
Stay Ahead of the Next One

Get instant alerts for legion of the bouncy castle inc. bc-csharp

Be the first to know when new unknown vulnerabilities affecting legion of the bouncy castle inc. bc-csharp are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Legion of the Bouncy Castle Inc. / bc-csharp
0 < 2.7.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/bcgit/bc-csharp/wiki/CVE-2026-103603 github.com: https://github.com/bcgit/bc-csharp/commit/f47ad47c7b5745b53d3f9ac711a5a419a272a5d7

Credits

Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research.