Description
Loop with unreachable exit condition in Pkcs12Store.GetCertificateChain in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who can supply a crafted PKCS#12 file to an application that loads it and requests a key entry's certificate chain to cause a denial of service, in which the call never returns and consumes CPU and memory until an OutOfMemoryException, via certificates whose issuer links form a cycle, for example two certificates whose AuthorityKeyIdentifier extensions each identify the other's public key. This happens because the chain-building loop stops only when no issuer is found or a certificate links to itself, and keeps no record of certificates already visited. The key-identifier links are followed without checking signatures.
Published: 2026-10-02
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service due to CPU and memory exhaustion
Action: Immediate Patch
AI Analysis

Impact

A flaw in the certificate chain construction routine of the Bouncy Castle C# library causes a loop with no reachable exit condition. When the application requests a certificate chain for a key entry in a PKCS#12 file, the code follows issuer links without keeping track of already visited certificates. If the issuer chain contains a cycle, the loop never terminates, continuously consuming CPU and memory until an OutOfMemoryException is raised. The resulting denial of service can be observed when the method never returns, leaving the host unresponsive. The vulnerability is identified as a CWE-835 loop with unreachable exit condition.

Affected Systems

Legion of the Bouncy Castle Inc. provides the bc‑csharp library. Versions prior to 2.7.0 are affected. Any .NET application that loads a PKCS#12 file and requests a certificate chain from bc‑csharp using these versions is vulnerable. The vulnerability was discovered in the bouncy castle csharp repository commit 1b8fad04.

Risk and Exploitability

The CVSS score of 7.1 indicates high severity. EPSS data is not available, and the issue is not listed in the CISA KEV catalog. Attackers must be able to supply a crafted PKCS#12 file to an application utilizing the vulnerable library; this is typically a local or controlled file input scenario. Based on the description, the likely attack vector is local file supply, but an application that accepts remote PKCS#12 uploads would also be at risk. Successful exploitation results in denial of service, with CPU and memory resources drained until the process throws an OutOfMemoryException. The fix requires upgrading the library version.

Generated by OpenCVE AI on October 2, 2026 at 09:05 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the bc‑csharp library to version 2.7.0 or newer.
  • Configure an application-level watchdog or timeout for certificate chain retrieval to prevent indefinite CPU usage.
  • Reject or sanitize any PKCS#12 files that exhibit issuer loops before invoking bc‑csharp functions.

Generated by OpenCVE AI on October 2, 2026 at 09:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 07:30:00 +0000

Type Values Removed Values Added
Description Loop with unreachable exit condition in Pkcs12Store.GetCertificateChain in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who can supply a crafted PKCS#12 file to an application that loads it and requests a key entry's certificate chain to cause a denial of service, in which the call never returns and consumes CPU and memory until an OutOfMemoryException, via certificates whose issuer links form a cycle, for example two certificates whose AuthorityKeyIdentifier extensions each identify the other's public key. This happens because the chain-building loop stops only when no issuer is found or a certificate links to itself, and keeps no record of certificates already visited. The key-identifier links are followed without checking signatures.
Title Pkcs12Store.GetCertificateChain loops forever on cyclic issuer links
Weaknesses CWE-835
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: bcorg

Published:

Updated: 2026-10-02T07:01:18.029Z

Reserved: 2026-07-16T23:48:46.076Z

Link: CVE-2026-63570

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-02T08:17:01.833

Modified: 2026-10-02T14:44:52.247

Link: CVE-2026-63570

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T09:15:08Z

Weaknesses
  • CWE-835

    Loop with Unreachable Exit Condition ('Infinite Loop')