Allocation of resources without limits in password-based private-key decryption (PbeUtilities.GenerateCipherParameters) in Legion of the Bouncy… (CVE-2026-63578)
A vulnerability in Legion of the Bouncy Castle Inc. bc-csharp before version 2.7.0 allows an attacker to cause a denial of service via CPU exhaustion. This occurs during password-based private-key decryption when an attacker supplies an encrypted private key with an iteration count close to 2^31, which is taken from unauthenticated algorithm parameters without an upper bound. The affected algorithms include PKCS#5 PBES1 and PBES2 (PBKDF2), PKCS#12 PBE algorithms, and CMS password recipients. This flaw enables resource exhaustion before password or data verification.
AI Analysis
Technical Summary
The vulnerability (CVE-2026-63578) exists in the PbeUtilities.GenerateCipherParameters function of Legion of the Bouncy Castle Inc. bc-csharp library versions prior to 2.7.0. It allows an attacker who can supply an encrypted private key (e.g., PKCS#8 EncryptedPrivateKeyInfo or PEM files labeled "ENCRYPTED PRIVATE KEY") to trigger excessive CPU usage by specifying an iteration count near 2^31. This count is extracted from unauthenticated algorithm parameters without an upper limit, causing the key derivation function to consume excessive resources before any password or data validation occurs. The vulnerability affects multiple password-based encryption algorithms including PKCS#5 PBES1, PBES2 (PBKDF2), PKCS#12 PBE algorithms, and CMS password recipients (CmsPbeKey). Related issues include CVE-2026-63572 and CVE-2026-63575, which cover PKCS#12 file loading and zero or negative iteration counts respectively.
Potential Impact
An attacker capable of supplying a crafted encrypted private key can cause a denial of service by exhausting CPU resources during the key derivation process. This can disrupt services or applications relying on the affected library for password-based private-key decryption. There is no indication of direct data compromise or privilege escalation from this vulnerability alone.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, avoid processing untrusted encrypted private keys or implement application-level limits on iteration counts used in password-based key derivation. Monitor vendor channels for updates regarding a patch or official mitigation.
Allocation of resources without limits in password-based private-key decryption (PbeUtilities.GenerateCipherParameters) in Legion of the Bouncy… (CVE-2026-63578)
Description
A vulnerability in Legion of the Bouncy Castle Inc. bc-csharp before version 2.7.0 allows an attacker to cause a denial of service via CPU exhaustion. This occurs during password-based private-key decryption when an attacker supplies an encrypted private key with an iteration count close to 2^31, which is taken from unauthenticated algorithm parameters without an upper bound. The affected algorithms include PKCS#5 PBES1 and PBES2 (PBKDF2), PKCS#12 PBE algorithms, and CMS password recipients. This flaw enables resource exhaustion before password or data verification.
CVSS v4.0
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability (CVE-2026-63578) exists in the PbeUtilities.GenerateCipherParameters function of Legion of the Bouncy Castle Inc. bc-csharp library versions prior to 2.7.0. It allows an attacker who can supply an encrypted private key (e.g., PKCS#8 EncryptedPrivateKeyInfo or PEM files labeled "ENCRYPTED PRIVATE KEY") to trigger excessive CPU usage by specifying an iteration count near 2^31. This count is extracted from unauthenticated algorithm parameters without an upper limit, causing the key derivation function to consume excessive resources before any password or data validation occurs. The vulnerability affects multiple password-based encryption algorithms including PKCS#5 PBES1, PBES2 (PBKDF2), PKCS#12 PBE algorithms, and CMS password recipients (CmsPbeKey). Related issues include CVE-2026-63572 and CVE-2026-63575, which cover PKCS#12 file loading and zero or negative iteration counts respectively.
Potential Impact
An attacker capable of supplying a crafted encrypted private key can cause a denial of service by exhausting CPU resources during the key derivation process. This can disrupt services or applications relying on the affected library for password-based private-key decryption. There is no indication of direct data compromise or privilege escalation from this vulnerability alone.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, avoid processing untrusted encrypted private keys or implement application-level limits on iteration counts used in password-based key derivation. Monitor vendor channels for updates regarding a patch or official mitigation.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-4583-5v2w-p3vq
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-63578"]
- Database Specific Severity
- HIGH
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6abfeeb5a43b0b3b89e55f86
Added to database: 10/02/2026, 17:49:41 UTC
Last enriched: 10/02/2026, 18:20:27 UTC
Last updated: 10/02/2026, 20:45:56 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.