Impact
The vulnerability resides in the PkixNameConstraintValidator of Bouncy Castle’s .NET library and allows an attacker who controls or can obtain certificates issued by a name‑constrained intermediate CA to bypass name constraints during PKIX path validation. By creating an rfc822Name, dNSName, or uniformResourceIdentifier that ends with a trailing dot, the validator compares the name against the excluded subtrees without stripping the root‑label dot, causing a fully qualified host to fail to match its excluding rule. This leads to a false validation of the certificate for an email, DNS name, or URI host that is actually excluded from the certificate’s authority, potentially granting the attacker unauthorized credential use. The weakness is formally identified as CWE‑295.
Affected Systems
The affected product is Bouncy Castle’s bc‑csharp library in versions before 2.7.0. The vulnerability is specific to the .NET implementation and affects any applications that rely on that library for performing PKIX certificate path validation without additional safeguards.
Risk and Exploitability
The CVSS score is 8.2, indicating high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting a lower publicly known exploitation rate at this time. Based on the description, the likely attack vector is an attacker who can generate or control certificates from a name‑constrained intermediate CA, which may be feasible in scenarios involving compromised certification authorities or in environments where the CA is partially trusted. Exploitation requires the vulnerability to be present in the validating application and the attacker to supply a malicious certificate chain that includes a name with a trailing dot that matches the intended target’s host.
OpenCVE Enrichment