๐Ÿ” CVE Alert

CVE-2026-63568

UNKNOWN 0.0

Unbounded CMP/CRMF password-based MAC iteration count allows CPU exhaustion

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Allocation of resources without limits or throttling in the CMP/CRMF password-based MAC verifier (PKMacBuilder) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote unauthenticated attacker to cause a denial of service through CPU exhaustion via a CMP message or CRMF certificate request whose PBMParameter declares a very large iteration count, because PKMacBuilder enforced its iteration-count ceiling only when the caller had supplied an explicit maximum through the PKMacBuilder(IPKMacPrimitivesProvider, int) constructor. With any other constructor, ProtectedPkiMessage.Verify and CertificateRequestMessage.IsValidSigningKeyPop performed as many hash iterations as the sender requested, up to about 2^31, before the MAC could be checked.

CWE CWE-770
Vendor legion of the bouncy castle inc.
Product bc-csharp
Published Oct 2, 2026
Stay Ahead of the Next One

Get instant alerts for legion of the bouncy castle inc. bc-csharp

Be the first to know when new unknown vulnerabilities affecting legion of the bouncy castle inc. bc-csharp are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Legion of the Bouncy Castle Inc. / bc-csharp
0 < 2.7.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/bcgit/bc-csharp/wiki/CVE-2026-63568 github.com: https://github.com/bcgit/bc-csharp/commit/10a9862fad04bb0c832a78b10e71d9818d6d1a63 github.com: https://github.com/bcgit/bc-csharp/commit/65283bae66843d0d3c13c5e0272dbbe1c0d6aa04 github.com: https://github.com/bcgit/bc-csharp/commit/d16f08a53dd0a78eb3310bbe80c947c7e1677290

Credits

Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research.