Description
Allocation of resources without limits in PKCS#12 keystore loading (Pkcs12Store.Load) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who can supply a PKCS#12 (PFX) file to cause a denial of service through CPU exhaustion via an iteration count close to 2^31 in the file's MacData or in the PBE parameters of an encrypted SafeContents or shrouded key bag, because the counts are taken from the file without an upper bound and the key derivation runs before the MAC or the password can be checked. A zero or negative count is covered by CVE-2026-63575. Pkcs12Utilities.ConvertToDefiniteLength is also affected.
Published: 2026-10-02
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via CPU exhaustion
Action: Patch Immediately
AI Analysis

Impact

An unbounded iteration count is read from a supplied PKCS#12 file during load time, allowing an attacker to specify a value near 2^31 for the MAC or PBE parameters. The key derivation process repeats the operation that many times before any MAC or password validation occurs, consuming CPU resources until the system becomes unresponsive. The vulnerability results in service interruption but does not provide direct data exfiltration or code execution.

Affected Systems

Legion of the Bouncy Castle Inc. bc-csharp prior to version 2.7.0 is affected. Both the PKCS#12 keystore loader (Pkcs12Store.Load) and the Pkcs12Utilities.ConvertToDefiniteLength functions lack bounds checking for iteration counts in MacData and shrouded key bags.

Risk and Exploitability

The CVSS score of 7.1 indicates a moderate to high severity for denial of service. EPSS data is not available, making the likelihood of exploitation difficult to gauge; however, the lack of a KEV listing suggests it has not yet been leveraged in the wild. An attacker who can supply a crafted PKCS#12 file to an application using bc‑csharp can trigger the CPU‑intensive loop, potentially affecting any system that loads untrusted keystore files.

Generated by OpenCVE AI on October 2, 2026 at 08:45 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade bc‑csharp to version 2.7.0 or later.
  • If an update is not immediately possible, validate any incoming PKCS#12 files to ensure iteration counts are within acceptable limits before loading them into bc‑csharp.
  • Consider replacing bc‑csharp with a library that enforces bounds on cryptographic parameters if the application continues to process untrusted keystore files.

Generated by OpenCVE AI on October 2, 2026 at 08:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 07:30:00 +0000

Type Values Removed Values Added
Description Allocation of resources without limits in PKCS#12 keystore loading (Pkcs12Store.Load) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who can supply a PKCS#12 (PFX) file to cause a denial of service through CPU exhaustion via an iteration count close to 2^31 in the file's MacData or in the PBE parameters of an encrypted SafeContents or shrouded key bag, because the counts are taken from the file without an upper bound and the key derivation runs before the MAC or the password can be checked. A zero or negative count is covered by CVE-2026-63575. Pkcs12Utilities.ConvertToDefiniteLength is also affected.
Title Unbounded MAC and bag-decryption iteration counts when loading PKCS#12 files
Weaknesses CWE-770
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: bcorg

Published:

Updated: 2026-10-02T07:04:37.676Z

Reserved: 2026-07-16T23:50:45.118Z

Link: CVE-2026-63572

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-02T08:17:02.157

Modified: 2026-10-02T14:44:52.247

Link: CVE-2026-63572

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T09:00:18Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling