Description
Improper certificate validation in PkixNameConstraintValidator in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who controls, or can obtain certificates from, a name-constrained intermediate CA to have certificates accepted during PKIX certification path validation for email addresses, DNS names or URI hosts that lie within excluded subtrees applying to that CA, via an rfc822Name, dNSName or uniformResourceIdentifier name whose host ends with a dot, because names and constraints were compared without first removing the RFC 1034 root-label trailing dot, so a fully qualified host name did not match an excluded subtree for the same host written without the dot.
Published: 2026-10-02
Score: 8.2 High
EPSS: n/a
KEV: No
Impact: Certificate validation bypass via trailing dot in name constraints
Action: Apply Patch
AI Analysis

Impact

The vulnerability resides in the PkixNameConstraintValidator of Bouncy Castle’s .NET library and allows an attacker who controls or can obtain certificates issued by a name‑constrained intermediate CA to bypass name constraints during PKIX path validation. By creating an rfc822Name, dNSName, or uniformResourceIdentifier that ends with a trailing dot, the validator compares the name against the excluded subtrees without stripping the root‑label dot, causing a fully qualified host to fail to match its excluding rule. This leads to a false validation of the certificate for an email, DNS name, or URI host that is actually excluded from the certificate’s authority, potentially granting the attacker unauthorized credential use. The weakness is formally identified as CWE‑295.

Affected Systems

The affected product is Bouncy Castle’s bc‑csharp library in versions before 2.7.0. The vulnerability is specific to the .NET implementation and affects any applications that rely on that library for performing PKIX certificate path validation without additional safeguards.

Risk and Exploitability

The CVSS score is 8.2, indicating high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting a lower publicly known exploitation rate at this time. Based on the description, the likely attack vector is an attacker who can generate or control certificates from a name‑constrained intermediate CA, which may be feasible in scenarios involving compromised certification authorities or in environments where the CA is partially trusted. Exploitation requires the vulnerability to be present in the validating application and the attacker to supply a malicious certificate chain that includes a name with a trailing dot that matches the intended target’s host.

Generated by OpenCVE AI on October 2, 2026 at 09:00 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to Bouncy Castle bc‑csharp 2.7.0 or later, which fixes the name‑constraint comparison issue.
  • If an upgrade is not immediately feasible, configure the application to reject any certificates containing rfc822Name, dNSName, or uniformResourceIdentifier values that end with a dot before performing PKIX validation.
  • Alternatively, implement a custom wrapper around the Bouncy Castle PKIX validation to normalize names by removing trailing root‑label dots or to enforce strict name‑constraint compliance.

Generated by OpenCVE AI on October 2, 2026 at 09:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 07:30:00 +0000

Type Values Removed Values Added
Description Improper certificate validation in PkixNameConstraintValidator in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who controls, or can obtain certificates from, a name-constrained intermediate CA to have certificates accepted during PKIX certification path validation for email addresses, DNS names or URI hosts that lie within excluded subtrees applying to that CA, via an rfc822Name, dNSName or uniformResourceIdentifier name whose host ends with a dot, because names and constraints were compared without first removing the RFC 1034 root-label trailing dot, so a fully qualified host name did not match an excluded subtree for the same host written without the dot.
Title Name constraints bypass via trailing dot in rfc822Name, dNSName and URI hosts
Weaknesses CWE-295
References
Metrics cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: bcorg

Published:

Updated: 2026-10-02T07:10:03.885Z

Reserved: 2026-09-30T23:01:10.053Z

Link: CVE-2026-103602

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-02T08:17:00.677

Modified: 2026-10-02T08:17:00.677

Link: CVE-2026-103602

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T09:15:08Z

Weaknesses
  • CWE-295

    Improper Certificate Validation