๐Ÿ” CVE Alert

CVE-2026-63577

UNKNOWN 0.0

Name Constraints bypass: directoryName constraint matched at any position in the DN instead of as a prefix

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Improper certificate validation in the directoryName name-constraint check (PkixNameConstraintValidator.WithinDNSubtree) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who controls, or can have certificates issued by, a name-constrained intermediate CA to get certificates accepted by PKIX path validation whose subject distinguished name, or a directoryName subjectAltName, lies outside the CA's permitted subtrees, via a name that places other RDNs ahead of a copy of the permitted RDN sequence, because the check looks for the constraint's first RDN anywhere in the name and compares the remaining RDNs from that position, instead of requiring the constraint to be an initial prefix of the name as RFC 5280 sections 4.2.1.10 and 7.1 require.

CWE CWE-295
Vendor legion of the bouncy castle inc.
Product bc-csharp
Published Oct 2, 2026
Stay Ahead of the Next One

Get instant alerts for legion of the bouncy castle inc. bc-csharp

Be the first to know when new unknown vulnerabilities affecting legion of the bouncy castle inc. bc-csharp are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Legion of the Bouncy Castle Inc. / bc-csharp
0 < 2.7.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/bcgit/bc-csharp/wiki/CVE-2026-63577 github.com: https://github.com/bcgit/bc-csharp/commit/606e9153b97a265c70ca8293d21ec859344d7de8 github.com: https://github.com/bcgit/bc-csharp/commit/75c3c576602886180ed92a63c89419e3bd63b392

Credits

Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research.