Description
Uncontrolled recursion in the ASN.1 parser (Asn1InputStream, Asn1StreamParser) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote unauthenticated attacker to cause a denial of service via a crafted ASN.1 encoding of deeply nested constructed elements (for example SEQUENCE inside SEQUENCE, in definite-length DER or indefinite-length BER form), because each nesting level is parsed by a further recursive call with no bound on depth. About 2,000 levels (8 KB of DER) are enough to exhaust a 1.5 MB thread stack, the .NET main-thread default on Windows, and raise a StackOverflowException, which .NET cannot catch and which terminates the whole process; on threads with larger stacks, parse time instead grows quadratically with depth (about 9 seconds of CPU for a 64 KB input). Any path that parses untrusted ASN.1 is exposed, including X.509 certificates and CRLs, CMS/PKCS#7, PKCS#8/PKCS#12, OCSP and TLS Certificate messages.
Published: 2026-10-02
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via stack overflow
Action: Patch Now
AI Analysis

Impact

The vulnerability is an unbounded recursion in the ASN.1 parser of Legion of the Bouncy Castle Inc.'s bc‑csharp library. It allows an unauthenticated attacker to send a deeply nested ASN.1 structure, such as a SEQUENCE inside SEQUENCE, that causes the parser to recurse level by level without a depth limit. In .NET the result is a StackOverflowException that terminates the entire process, or, on larger stack threads, causes the parse time to grow quadratically until the stack is exhausted. The attack is a classic denial of service, potentially impacting any service that parses untrusted ASN.1 data, including certificate validation, CMS/PKCS#7, PKCS#8/PKCS#12, OCSP, and TLS certificate messages.

Affected Systems

The flaw affects all versions of the bc‑csharp library before 2.7.0 distributed by Legion of the Bouncy Castle Inc. Any application that uses bc‑csharp to parse X.509 certificates, CRLs, CMS/PKCS#7, PKCS#8/PKCS#12, OCSP, or TLS certificate messages is potentially vulnerable. Users of older versions should examine whether their deployment includes these codecs and consider whether it receives untrusted ASN.1 input.

Risk and Exploitability

The CVSS score of 8.7 reflects a high severity denial of service that is reachable from remote unauthenticated users. EPSS is not reported, but the flaw was discovered by the maintainer and availed via public source commits, indicating that exploitation could be practical. The vulnerability is not listed in CISA's KEV catalog. The likely attack vector is remote network exploitation; an attacker can craft a malicious ASN.1 blob that triggers the recursive parsing and stack exhaustion. Once triggered the vulnerable process terminates, causing service interruption for affected applications.

Generated by OpenCVE AI on October 2, 2026 at 08:45 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the bc‑csharp library to version 2.7.0 or newer, which introduces a depth limit on ASN.1 parsing and removes the unbounded recursion.
  • If upgrading is not immediately possible, isolate the parsing routine in a separate process or worker thread with a smaller stack size, and reject or properly constrain any deeply nested ASN.1 inputs.
  • Consider disabling or restricting libraries that parse untrusted ASN.1 data in the production environment until a patch is applied.

Generated by OpenCVE AI on October 2, 2026 at 08:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 07:30:00 +0000

Type Values Removed Values Added
Description Uncontrolled recursion in the ASN.1 parser (Asn1InputStream, Asn1StreamParser) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote unauthenticated attacker to cause a denial of service via a crafted ASN.1 encoding of deeply nested constructed elements (for example SEQUENCE inside SEQUENCE, in definite-length DER or indefinite-length BER form), because each nesting level is parsed by a further recursive call with no bound on depth. About 2,000 levels (8 KB of DER) are enough to exhaust a 1.5 MB thread stack, the .NET main-thread default on Windows, and raise a StackOverflowException, which .NET cannot catch and which terminates the whole process; on threads with larger stacks, parse time instead grows quadratically with depth (about 9 seconds of CPU for a 64 KB input). Any path that parses untrusted ASN.1 is exposed, including X.509 certificates and CRLs, CMS/PKCS#7, PKCS#8/PKCS#12, OCSP and TLS Certificate messages.
Title Unbounded ASN.1 nesting depth causes process-terminating stack overflow
Weaknesses CWE-674
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: bcorg

Published:

Updated: 2026-10-02T07:08:51.653Z

Reserved: 2026-09-30T23:01:10.053Z

Link: CVE-2026-103600

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-02T08:17:00.363

Modified: 2026-10-02T14:44:52.247

Link: CVE-2026-103600

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T08:45:07Z

Weaknesses