Description
Allocation of resources without limits in password-based private-key decryption (PbeUtilities.GenerateCipherParameters) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who can supply an encrypted private key, such as a PKCS#8 EncryptedPrivateKeyInfo or "ENCRYPTED PRIVATE KEY" PEM file, to cause a denial of service through CPU exhaustion via an iteration count close to 2^31, because the count is taken from the unauthenticated algorithm parameters without an upper bound and the key derivation runs before the password or the data can be checked. PKCS#5 PBES1 and PBES2 (PBKDF2), the PKCS#12 PBE algorithms and CMS password recipients (CmsPbeKey) are affected. Loading PKCS#12 files with Pkcs12Store is covered by CVE-2026-63572, and a zero or negative count with the PKCS#12 algorithms by CVE-2026-63575.
Published: 2026-10-02
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

Allocation of resources without limits during password‑based decryption of PKCS#8 private keys allows an attacker to supply a key file with an iteration count near 2^31. The derivation function then consumes excessive CPU, leading to denial of service. The flaw resides in the PbeUtilities.GenerateCipherParameters routine of Bouncy Castle bc‑csharp versions prior to 2.7.0 and affects PBES1, PBES2, PBKDF2, PKCS#12, and CMS password recipient schemes.

Affected Systems

Legion of the Bouncy Castle Inc. publishes the bc‑csharp library for .NET. Versions older than 2.7.0 of bc‑csharp are vulnerable. Applications that use this library to load or process encrypted PKCS#8, PKCS#12, or CMS files may be exploitable. No specific vendor or product beyond the library is listed.

Risk and Exploitability

The CVSS v3.1 score of 7.1 indicates a moderate impact. The EPSS score is not available, and the vulnerability is not in the CISA KEV catalog. Because the attacker must provide an encrypted key file, the attack is likely local or requires the ability to influence the input processed by the application. The lack of input validation on the iteration count presents a straightforward denial‑of‑service vector through CPU exhaustion.

Generated by OpenCVE AI on October 2, 2026 at 09:01 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the bc‑csharp library to version 2.7.0 or later.
  • If an upgrade is not feasible, enforce a maximum iteration count in the application before invoking PBE to limit CPU consumption.
  • Validate encrypted key parameters and reject keys with iteration counts near the maximum value.
  • Monitor application CPU usage for spikes and apply rate limiting to key decryption operations.

Generated by OpenCVE AI on October 2, 2026 at 09:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 07:30:00 +0000

Type Values Removed Values Added
Description Allocation of resources without limits in password-based private-key decryption (PbeUtilities.GenerateCipherParameters) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who can supply an encrypted private key, such as a PKCS#8 EncryptedPrivateKeyInfo or "ENCRYPTED PRIVATE KEY" PEM file, to cause a denial of service through CPU exhaustion via an iteration count close to 2^31, because the count is taken from the unauthenticated algorithm parameters without an upper bound and the key derivation runs before the password or the data can be checked. PKCS#5 PBES1 and PBES2 (PBKDF2), the PKCS#12 PBE algorithms and CMS password recipients (CmsPbeKey) are affected. Loading PKCS#12 files with Pkcs12Store is covered by CVE-2026-63572, and a zero or negative count with the PKCS#12 algorithms by CVE-2026-63575.
Title Unbounded PBE iteration count when decrypting PKCS#8 private keys
Weaknesses CWE-770
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: bcorg

Published:

Updated: 2026-10-02T07:08:15.987Z

Reserved: 2026-07-16T23:51:51.307Z

Link: CVE-2026-63578

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-02T08:17:03.087

Modified: 2026-10-02T14:44:52.247

Link: CVE-2026-63578

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T09:15:08Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling