Description
Improper input validation in DHAgreement.CalculateAgreement (MTI/A0 two-pass Diffie-Hellman) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an on-path attacker to make the local party compute an agreed value the attacker already knows, defeating the key authentication MTI/A0 is meant to provide. It also allows a malicious peer to learn the local static private key modulo the small factors of p-1, and to recover it entirely in groups with many such factors. The attack uses a crafted out-of-range or small-order ephemeral value, and works because that value is raised to the static private key without the range and subgroup-membership checks applied to DH public keys. Only applications that call DHAgreement directly are affected.
Published: 2026-10-02
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Key Compromise via Invalid DH Ephemeral Value
Action: Immediate Patch
AI Analysis

Impact

Improper input validation in the DHAgreement.CalculateAgreement method of the MTI/A0 two‑pass Diffie‑Hellman implementation allows an attacker to supply a crafted out‑of‑range or small‑order public value. This causes the endpoint to compute an agreed value that the attacker already knows, removing the assurance that the derived key is authentic. The flaw also enables a malicious peer to recover the local static private key modulo small factors of p‑1, and in some groups to recover the full key. The result is a fundamental loss of confidentiality and authentication.

Affected Systems

The vulnerability affects the Legion of the Bouncy Castle Inc. bc‑csharp library in all releases before 2.7.0 on any platform where applications invoke DHAgreement directly for key agreement using MTI/A0. Systems that employ this library for secure communications or cryptographic protocols are potentially impacted.

Risk and Exploitability

The flaw is quantified with a CVSS score of 9.1, indicating high severity. No EPSS score is available, but the vulnerability does not appear in CISA’s KEV catalog. An on‑path attacker or a malicious peer can exploit the flaw by injecting a crafted public key; successful exploitation results in the local party deriving a known shared secret and revealing its static private key in certain configurations. The attack is relatively straightforward for anyone able to influence the peer’s DH public value.

Generated by OpenCVE AI on October 2, 2026 at 08:48 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the bc‑csharp library to version 2.7.0 or later to obtain the upstream validation fix.
  • If upgrading is delayed, avoid calling DHAgreement directly; use higher‑level APIs that enforce public key validation provided by the library or a framework.
  • Apply the patch from commit fe236ad2 as an interim measure, which adds proper range and subgroup checks for the public value.

Generated by OpenCVE AI on October 2, 2026 at 08:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 07:15:00 +0000

Type Values Removed Values Added
Description Improper input validation in DHAgreement.CalculateAgreement (MTI/A0 two-pass Diffie-Hellman) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an on-path attacker to make the local party compute an agreed value the attacker already knows, defeating the key authentication MTI/A0 is meant to provide. It also allows a malicious peer to learn the local static private key modulo the small factors of p-1, and to recover it entirely in groups with many such factors. The attack uses a crafted out-of-range or small-order ephemeral value, and works because that value is raised to the static private key without the range and subgroup-membership checks applied to DH public keys. Only applications that call DHAgreement directly are affected.
Title MTI/A0 DHAgreement does not validate the peer's ephemeral value
Weaknesses CWE-20
References
Metrics cvssV4_0

{'score': 9.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: bcorg

Published:

Updated: 2026-10-02T07:00:23.526Z

Reserved: 2026-07-16T23:48:46.076Z

Link: CVE-2026-63569

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-02T07:16:37.430

Modified: 2026-10-02T14:44:52.247

Link: CVE-2026-63569

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T09:00:18Z

Weaknesses
  • CWE-20

    Improper Input Validation