CVE-2026-103602: CWE-295 Improper Certificate Validation in Legion of the Bouncy Castle Inc. bc-csharp
Improper certificate validation in PkixNameConstraintValidator in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who controls, or can obtain certificates from, a name-constrained intermediate CA to have certificates accepted during PKIX certification path validation for email addresses, DNS names or URI hosts that lie within excluded subtrees applying to that CA, via an rfc822Name, dNSName or uniformResourceIdentifier name whose host ends with a dot, because names and constraints were compared without first removing the RFC 1034 root-label trailing dot, so a fully qualified host name did not match an excluded subtree for the same host written without the dot.
AI Analysis
Technical Summary
CVE-2026-103602 describes an improper certificate validation vulnerability in the PkixNameConstraintValidator of Legion of the Bouncy Castle Inc. bc-csharp prior to version 2.7.0. The vulnerability occurs because the validation logic does not remove the RFC 1034 root-label trailing dot when comparing names and constraints. As a result, certificates issued by a name-constrained intermediate CA can be accepted for email addresses, DNS names, or URI hosts that should be excluded by the name constraints if the host name ends with a dot. This allows an attacker controlling or able to obtain certificates from such a CA to bypass intended restrictions during PKIX certification path validation.
Potential Impact
An attacker who controls or can obtain certificates from a name-constrained intermediate CA can have certificates accepted for names that should be excluded by the name constraints. This undermines the trust model of PKIX certification path validation for email addresses, DNS names, or URI hosts, potentially allowing unauthorized certificates to be trusted.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or patch information is provided in the available data. Until a fix is available, users should be cautious when trusting certificates from name-constrained intermediate CAs and monitor vendor communications for updates.
CVE-2026-103602: CWE-295 Improper Certificate Validation in Legion of the Bouncy Castle Inc. bc-csharp
Description
Improper certificate validation in PkixNameConstraintValidator in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who controls, or can obtain certificates from, a name-constrained intermediate CA to have certificates accepted during PKIX certification path validation for email addresses, DNS names or URI hosts that lie within excluded subtrees applying to that CA, via an rfc822Name, dNSName or uniformResourceIdentifier name whose host ends with a dot, because names and constraints were compared without first removing the RFC 1034 root-label trailing dot, so a fully qualified host name did not match an excluded subtree for the same host written without the dot.
CVSS v4.0
Score 8.2high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-103602 describes an improper certificate validation vulnerability in the PkixNameConstraintValidator of Legion of the Bouncy Castle Inc. bc-csharp prior to version 2.7.0. The vulnerability occurs because the validation logic does not remove the RFC 1034 root-label trailing dot when comparing names and constraints. As a result, certificates issued by a name-constrained intermediate CA can be accepted for email addresses, DNS names, or URI hosts that should be excluded by the name constraints if the host name ends with a dot. This allows an attacker controlling or able to obtain certificates from such a CA to bypass intended restrictions during PKIX certification path validation.
Potential Impact
An attacker who controls or can obtain certificates from a name-constrained intermediate CA can have certificates accepted for names that should be excluded by the name constraints. This undermines the trust model of PKIX certification path validation for email addresses, DNS names, or URI hosts, potentially allowing unauthorized certificates to be trusted.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or patch information is provided in the available data. Until a fix is available, users should be cautious when trusting certificates from name-constrained intermediate CAs and monitor vendor communications for updates.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-mx2f-845p-2h26
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-103602"]
- Database Specific Severity
- HIGH
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6abfeeb7a43b0b3b89e560a1
Added to database: 10/02/2026, 17:49:43 UTC
Last enriched: 10/02/2026, 18:21:07 UTC
Last updated: 10/02/2026, 22:45:56 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.