๐Ÿ” CVE Alert

CVE-2026-63576

UNKNOWN 0.0

URI name constraints checked against a mis-parsed host

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Improper certificate validation in PkixNameConstraintValidator (ExtractHostFromURL) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a name-constrained subordinate CA, or anyone able to obtain certificates with chosen subjectAltName URIs from such a CA, to bypass permitted or excluded uniformResourceIdentifier name constraints during certification path validation via a URI whose path, query, fragment or userinfo contains characters such as '@' or ':', because the host was extracted by string slicing without first isolating the RFC 3986 authority component, so the host compared against the constraints could differ from the URI's actual host.

CWE CWE-295
Vendor legion of the bouncy castle inc.
Product bc-csharp
Published Oct 2, 2026
Stay Ahead of the Next One

Get instant alerts for legion of the bouncy castle inc. bc-csharp

Be the first to know when new unknown vulnerabilities affecting legion of the bouncy castle inc. bc-csharp are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Legion of the Bouncy Castle Inc. / bc-csharp
0 < 2.7.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/bcgit/bc-csharp/wiki/CVE-2026-63576 github.com: https://github.com/bcgit/bc-csharp/commit/f196a22bbf7765cc19b0c4f4645c74ea7ad35e09

Credits

Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research.