Description
Inefficient algorithmic complexity in X.509 distinguished name string conversion (X509Name.ToString and IetfUtilities.ValueToString) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote unauthenticated attacker to cause a denial of service through CPU exhaustion via a certificate, CRL, certification request or other structure whose name contains a long attribute value made up of characters that must be escaped, such as commas, or of leading or trailing spaces, because each escaping backslash was inserted into the buffer being scanned, so the work grew quadratically with the length of the value. Applications are exposed when they convert such a name to a string, for example to log or display it, or compare it with IetfUtilities.RdnAreEqual, as PKIX path validation does for directoryName name constraints.
Published: 2026-10-02
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

The defect is a quadratic‑time algorithm used during X.509 distinguished name string conversion when escaping characters such as commas or spaces. Each required backslash is inserted repeatedly as the buffer is scanned, so the processing effort grows proportional to the square of the attribute value length. An attacker can supply a certificate, CRL, request, or other structure with a very long attribute containing many such characters, forcing the library to consume an excessive amount of CPU time and causing a denial‑of‑service. The weakness is a classic inefficient algorithm (CWE‑407).

Affected Systems

This vulnerability applies to the bc‑csharp library from Legion of the Bouncy Castle Inc. Any build before version 2.7.0 is affected. Systems that convert certificates to strings, log them, or perform PKIX path validation relying on name‑constraint checks may be exposed.

Risk and Exploitability

The CVSS score of 8.7 indicates a high‑severity impact and the flaw is remote and unauthenticated. Even though no EPSS score is available, the lack of countermeasures means an attacker can trigger CPU exhaustion by submitting a maliciously crafted distinguished name over any network interface that accepts certificates. The vulnerability is not listed in the CISA KEV catalog, but its potential to disrupt critical services makes it a top priority. The attack vector is remote, unauthenticated, and depends solely on parsing a crafted name.

Generated by OpenCVE AI on October 2, 2026 at 08:41 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the bc‑csharp library to version 2.7.0 or later.
  • If upgrading is not currently possible, avoid calling X509Name.ToString or IetfUtilities.ValueToString with untrusted input; instead route such data through a safe parser or a non‑vulnerable library.
  • Implement monitoring or rate limiting on certificate processing to detect and mitigate excessive CPU usage, and consider disabling name‑constraint validation if it is not required.

Generated by OpenCVE AI on October 2, 2026 at 08:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 07:30:00 +0000

Type Values Removed Values Added
Description Inefficient algorithmic complexity in X.509 distinguished name string conversion (X509Name.ToString and IetfUtilities.ValueToString) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote unauthenticated attacker to cause a denial of service through CPU exhaustion via a certificate, CRL, certification request or other structure whose name contains a long attribute value made up of characters that must be escaped, such as commas, or of leading or trailing spaces, because each escaping backslash was inserted into the buffer being scanned, so the work grew quadratically with the length of the value. Applications are exposed when they convert such a name to a string, for example to log or display it, or compare it with IetfUtilities.RdnAreEqual, as PKIX path validation does for directoryName name constraints.
Title Quadratic-time escaping when converting X.509 distinguished names to strings
Weaknesses CWE-407
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: bcorg

Published:

Updated: 2026-10-02T07:11:04.012Z

Reserved: 2026-09-30T23:01:10.053Z

Link: CVE-2026-103604

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-02T08:17:00.980

Modified: 2026-10-02T08:17:00.980

Link: CVE-2026-103604

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T08:45:07Z

Weaknesses
  • CWE-407

    Inefficient Algorithmic Complexity