Impact
The defect is a quadratic‑time algorithm used during X.509 distinguished name string conversion when escaping characters such as commas or spaces. Each required backslash is inserted repeatedly as the buffer is scanned, so the processing effort grows proportional to the square of the attribute value length. An attacker can supply a certificate, CRL, request, or other structure with a very long attribute containing many such characters, forcing the library to consume an excessive amount of CPU time and causing a denial‑of‑service. The weakness is a classic inefficient algorithm (CWE‑407).
Affected Systems
This vulnerability applies to the bc‑csharp library from Legion of the Bouncy Castle Inc. Any build before version 2.7.0 is affected. Systems that convert certificates to strings, log them, or perform PKIX path validation relying on name‑constraint checks may be exposed.
Risk and Exploitability
The CVSS score of 8.7 indicates a high‑severity impact and the flaw is remote and unauthenticated. Even though no EPSS score is available, the lack of countermeasures means an attacker can trigger CPU exhaustion by submitting a maliciously crafted distinguished name over any network interface that accepts certificates. The vulnerability is not listed in the CISA KEV catalog, but its potential to disrupt critical services makes it a top priority. The attack vector is remote, unauthenticated, and depends solely on parsing a crafted name.
OpenCVE Enrichment