Description
Improper certificate validation in the directoryName name-constraint check (PkixNameConstraintValidator.WithinDNSubtree) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who controls, or can have certificates issued by, a name-constrained intermediate CA to get certificates accepted by PKIX path validation whose subject distinguished name, or a directoryName subjectAltName, lies outside the CA's permitted subtrees, via a name that places other RDNs ahead of a copy of the permitted RDN sequence, because the check looks for the constraint's first RDN anywhere in the name and compares the remaining RDNs from that position, instead of requiring the constraint to be an initial prefix of the name as RFC 5280 sections 4.2.1.10 and 7.1 require.
Published: 2026-10-02
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Authentication Bypass (Certificate Trust)
Action: Immediate Patch
AI Analysis

Impact

Improper certificate validation during directoryName name‑constraint checks in Bouncy Castle bc‑csharp allows an attacker who controls a name‑constrained intermediate CA to acquire certificates that are accepted by PKIX path validation even though their distinguished name or directoryName subjectAltName lies outside the CA’s permitted subtrees. The flaw originates in the validator that searches for the constraint’s first RDN anywhere within the certificate’s distinguished name and compares the remaining RDNs from that position, instead of requiring the constraint to be an initial prefix as defined by RFC 5280.

Affected Systems

The vulnerability affects the Bouncy Castle bc‑csharp library supplied by the Legion of the Bouncy Castle Inc. for all releases prior to version 2.7.0. Any system using these library versions for certificate path validation is susceptible.

Risk and Exploitability

With a CVSS score of 8.2 the vulnerability is rated high severity. Exploitation requires the attacker to control certificate issuance or to have a name‑constrained intermediate CA available; once a forged certificate chain is forged, it can be trusted by any application using the affected library, enabling impersonation or man‑in‑the‑middle attacks. The EPSS score is not available and the issue is not listed in CISA’s KEV catalog, but the risk remains substantial in environments that rely on Bouncy Castle for TLS or certificate validation.

Generated by OpenCVE AI on October 2, 2026 at 09:02 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the bc‑csharp library to version 2.7.0 or later, which corrects the name‑constraint validation logic.
  • If an upgrade cannot be performed immediately, avoid trusting certificates issued by name‑constrained intermediates unless you manually verify that their distinguished names match the permitted subtree; consider implementing the check in application code.
  • Re‑validate existing trusted certificate chains against the corrected RFC specification to ensure no bypassable certificates remain trusted.

Generated by OpenCVE AI on October 2, 2026 at 09:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 07:30:00 +0000

Type Values Removed Values Added
Description Improper certificate validation in the directoryName name-constraint check (PkixNameConstraintValidator.WithinDNSubtree) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who controls, or can have certificates issued by, a name-constrained intermediate CA to get certificates accepted by PKIX path validation whose subject distinguished name, or a directoryName subjectAltName, lies outside the CA's permitted subtrees, via a name that places other RDNs ahead of a copy of the permitted RDN sequence, because the check looks for the constraint's first RDN anywhere in the name and compares the remaining RDNs from that position, instead of requiring the constraint to be an initial prefix of the name as RFC 5280 sections 4.2.1.10 and 7.1 require.
Title Name Constraints bypass: directoryName constraint matched at any position in the DN instead of as a prefix
Weaknesses CWE-295
References
Metrics cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: bcorg

Published:

Updated: 2026-10-02T07:07:35.458Z

Reserved: 2026-07-16T23:51:51.306Z

Link: CVE-2026-63577

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-02T08:17:02.937

Modified: 2026-10-02T14:44:52.247

Link: CVE-2026-63577

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T09:15:08Z

Weaknesses
  • CWE-295

    Improper Certificate Validation