Vulnerability Description
Allocation of resources without limits in PKCS#12 keystore loading (Pkcs12Store.Load) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who can supply a PKCS#12 (PFX) file to cause a denial of service through CPU exhaustion via an iteration count close to 2^31 in the file's MacData or in the PBE parameters of an encrypted SafeContents or shrouded key bag, because the counts are taken from the file without an upper bound and the key derivation runs before the MAC or the password can be checked. A zero or negative count is covered by CVE-2026-63575. Pkcs12Utilities.ConvertToDefiniteLength is also affected.
Related Weaknesses (CWE)
References
- https://github.com/bcgit/bc-csharp/commit/34a7c05f719c91c024f285c6b420d3c00f8019
- https://github.com/bcgit/bc-csharp/commit/54ea0b179ee627027829b44c45d6dd32e575bd
- https://github.com/bcgit/bc-csharp/commit/7c0ed15f9783c9595b1a53f3900136461fd944
- https://github.com/bcgit/bc-csharp/commit/b57165ecb7790ecea08273b219d52d80c12990
- https://github.com/bcgit/bc-csharp/commit/c00fc018fca89c077c64dd2a2a2eb00ae7d972
- https://github.com/bcgit/bc-csharp/wiki/CVE-2026-63572
FAQ
What is CVE-2026-63572?
CVE-2026-63572 is a documented vulnerability. Allocation of resources without limits in PKCS#12 keystore loading (Pkcs12Store.Load) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who can supply a PKCS#12 (PFX) file ...
How severe is CVE-2026-63572?
CVSS scoring is not yet available for CVE-2026-63572. Check NVD for updates.
Is there a patch for CVE-2026-63572?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.