Impact
The vulnerability is an unbounded recursion in the ASN.1 parser of Legion of the Bouncy Castle Inc.'s bc‑csharp library. It allows an unauthenticated attacker to send a deeply nested ASN.1 structure, such as a SEQUENCE inside SEQUENCE, that causes the parser to recurse level by level without a depth limit. In .NET the result is a StackOverflowException that terminates the entire process, or, on larger stack threads, causes the parse time to grow quadratically until the stack is exhausted. The attack is a classic denial of service, potentially impacting any service that parses untrusted ASN.1 data, including certificate validation, CMS/PKCS#7, PKCS#8/PKCS#12, OCSP, and TLS certificate messages.
Affected Systems
The flaw affects all versions of the bc‑csharp library before 2.7.0 distributed by Legion of the Bouncy Castle Inc. Any application that uses bc‑csharp to parse X.509 certificates, CRLs, CMS/PKCS#7, PKCS#8/PKCS#12, OCSP, or TLS certificate messages is potentially vulnerable. Users of older versions should examine whether their deployment includes these codecs and consider whether it receives untrusted ASN.1 input.
Risk and Exploitability
The CVSS score of 8.7 reflects a high severity denial of service that is reachable from remote unauthenticated users. EPSS is not reported, but the flaw was discovered by the maintainer and availed via public source commits, indicating that exploitation could be practical. The vulnerability is not listed in CISA's KEV catalog. The likely attack vector is remote network exploitation; an attacker can craft a malicious ASN.1 blob that triggers the recursive parsing and stack exhaustion. Once triggered the vulnerable process terminates, causing service interruption for affected applications.
OpenCVE Enrichment