๐Ÿ” CVE Alert

CVE-2026-63570

UNKNOWN 0.0

Pkcs12Store.GetCertificateChain loops forever on cyclic issuer links

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Loop with unreachable exit condition in Pkcs12Store.GetCertificateChain in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who can supply a crafted PKCS#12 file to an application that loads it and requests a key entry's certificate chain to cause a denial of service, in which the call never returns and consumes CPU and memory until an OutOfMemoryException, via certificates whose issuer links form a cycle, for example two certificates whose AuthorityKeyIdentifier extensions each identify the other's public key. This happens because the chain-building loop stops only when no issuer is found or a certificate links to itself, and keeps no record of certificates already visited. The key-identifier links are followed without checking signatures.

CWE CWE-835
Vendor legion of the bouncy castle inc.
Product bc-csharp
Published Oct 2, 2026
Stay Ahead of the Next One

Get instant alerts for legion of the bouncy castle inc. bc-csharp

Be the first to know when new unknown vulnerabilities affecting legion of the bouncy castle inc. bc-csharp are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Legion of the Bouncy Castle Inc. / bc-csharp
0 < 2.7.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/bcgit/bc-csharp/wiki/CVE-2026-63570 github.com: https://github.com/bcgit/bc-csharp/commit/1b8fad04df4953230c9951c57678ee45c8aead85

Credits

Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research.