Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

bc-csharp — Vulnerabilities & Security Advisories 21

All 21 CVE vulnerabilities found in bc-csharp, with AI-generated Chinese analysis, references, and POCs.

This page documents known vulnerabilities associated with the bc-csharp product, categorizing them by weakness type and providing a comprehensive tag-based index for security researchers and developers. It aggregates data from multiple public sources to create a consolidated view of security issues affecting this specific cryptographic library, ensuring that users can access accurate and up-to-date information in one centralized location. The collection covers security incidents reported from 2015 through the present, capturing the full lifecycle of disclosed weaknesses as they emerge and are patched by the community. Visitors can use this resource to track vendor advisories and monitor the remediation progress of identified flaws, gain a deeper understanding of the underlying weakness classes that impact the codebase, and look up the complete vulnerability history of the product to assess long-term risk exposure. By organizing these entries chronologically and thematically, the page facilitates effective security auditing and helps teams prioritize updates based on severity and relevance. This structured approach supports informed decision-making regarding patch deployment and dependency management, allowing organizations to mitigate risks proactively rather than reactively. The data is sourced from official advisories, bug trackers, and third-party security databases, ensuring a reliable record of past and present threats. Users are encouraged to cross-reference this information with official product documentation for implementation-specific guidance on resolving the listed issues.

Vendor: Legion of the Bouncy Castle Inc.

CVE ID Title CVSS Severity Published
CVE-2026-103604 Quadratic-time escaping when converting X.509 distinguished names to strings CWE-407 8.7 High 2026-10-02
CVE-2026-103603 Unbounded HSS public key level count allows huge array allocation during signature verification CWE-789 8.7 High 2026-10-02
CVE-2026-103602 Name constraints bypass via trailing dot in rfc822Name, dNSName and URI hosts CWE-295 8.2 High 2026-10-02
CVE-2026-103601 CcmBlockCipher and KCcmBlockCipher leave unverified plaintext in the output buffer after a failed tag check CWE-354 8.2 High 2026-10-02
CVE-2026-103600 Unbounded ASN.1 nesting depth causes process-terminating stack overflow CWE-674 8.7 High 2026-10-02
CVE-2026-63578 Unbounded PBE iteration count when decrypting PKCS#8 private keys CWE-770 7.1 High 2026-10-02
CVE-2026-63577 Name Constraints bypass: directoryName constraint matched at any position in the DN instead of as a prefix CWE-295 8.2 High 2026-10-02
CVE-2026-63576 URI name constraints checked against a mis-parsed host CWE-295 8.2 High 2026-10-02
CVE-2026-63575 PKCS#12 key derivation loops about 2^32 times on a zero or negative iteration count CWE-835 7.1 High 2026-10-02
CVE-2026-63574 Unbounded allocation from OpenPGP signature and user attribute subpacket lengths CWE-789 8.7 High 2026-10-02
CVE-2026-63573 Bleichenbacher padding oracle in CMS RSA PKCS#1 v1.5 key-transport unwrap CWE-203 8.2 High 2026-10-02
CVE-2026-63572 Unbounded MAC and bag-decryption iteration counts when loading PKCS#12 files CWE-770 7.1 High 2026-10-02
CVE-2026-63571 Attribute certificate path validation does not verify the attribute certificate's signature CWE-347 8.7 High 2026-10-02
CVE-2026-63570 Pkcs12Store.GetCertificateChain loops forever on cyclic issuer links CWE-835 7.1 High 2026-10-02
CVE-2026-63569 MTI/A0 DHAgreement does not validate the peer's ephemeral value CWE-20 9.1 Critical 2026-10-02
CVE-2026-63568 Unbounded CMP/CRMF password-based MAC iteration count allows CPU exhaustion CWE-770 8.7 High 2026-10-02
CVE-2026-63567 IesEngine block-cipher mode checks padding before MAC (CBC padding oracle) CWE-203 8.2 High 2026-10-02
CVE-2026-63566 DTLS handshake reassembler allocates buffer from unchecked 24-bit length CWE-789 8.7 High 2026-10-02
CVE-2026-16001 IesEngine stream-mode MAC forgery via length-dependent KDF split CWE-354 8.2 High 2026-10-02
CVE-2026-16000 KCcmBlockCipher (DSTU 7624 CCM) tag not bound to nonce when no associated data is used CWE-325 8.7 High 2026-10-02
CVE-2026-15999 AES-CCM decryption accepts zero or out-of-range tag length, bypassing authentication CWE-354 8.2 High 2026-10-02

All 21 known CVE vulnerabilities affecting bc-csharp with full Chinese analysis, references, and POCs where available.