Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:nuget/bc-csharp

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-63577 is a vulnerability in Legion of the Bouncy Castle Inc. bc-csharp before version 2.7.0 involving improper certificate validation. The flaw occurs in the directoryName name-constraint check within the PkixNameConstraintValidator.WithinDNSubtree function. It allows an attacker controlling or having certificates issued by a name-constrained intermediate CA to bypass PKIX path validation by crafting subject distinguished names or directoryName subjectAltNames that lie outside the permitted subtrees. This happens because the validation incorrectly searches for the constraint's first RDN anywhere in the name rather than requiring it as an initial prefix, violating RFC 5280 requirements. No patch or remediation information is provided. The vulnerability is rated high severity based on the described impact.

Join the discussion

A vulnerability in Legion of the Bouncy Castle Inc. bc-csharp before version 2.7.0 allows an attacker to cause a denial of service via CPU exhaustion. This occurs during password-based private-key decryption when an attacker supplies an encrypted private key with an iteration count close to 2^31, which is taken from unauthenticated algorithm parameters without an upper bound. The affected algorithms include PKCS#5 PBES1 and PBES2 (PBKDF2), PKCS#12 PBE algorithms, and CMS password recipients. This flaw enables resource exhaustion before password or data verification.

Join the discussion

A vulnerability in Legion of the Bouncy Castle Inc. bc-csharp before version 2.7.0 allows remote attackers to cause a denial of service via crafted OpenPGP subpackets. The issue arises from memory allocation with an excessive size value in the OpenPGP signature and user attribute subpacket parsers, which can lead to an OutOfMemoryException or memory exhaustion during parsing.

Join the discussion

A vulnerability in the PKCS#12 key derivation implementation (Pkcs12ParametersGenerator) in Legion of the Bouncy Castle Inc. bc-csharp before version 2.7.0 allows an attacker to cause a denial of service via CPU exhaustion. This occurs when a PKCS#12 (PFX) file or PKCS#8 encrypted private key uses a PKCS#12 password-based encryption algorithm with an iteration count of zero or below. The derivation loop runs until its counter equals the count, but for zero or negative counts, it wraps around causing approximately 2^32 iterations, significantly delaying processing.

Join the discussion

A vulnerability in the Legion of the Bouncy Castle Inc. bc-csharp library before version 2.7.0 allows improper verification of cryptographic signatures in the attribute certificate path validator. This flaw permits a remote attacker to present a forged X.509 attribute certificate that is accepted as valid, potentially granting unauthorized roles or privileges. The issue arises because the validation process checks certification paths, validity periods, extensions, and revocation status but fails to verify the attribute certificate's signature using the issuer's public key. Only applications using the affected classes for attribute certificate validation are impacted.

Join the discussion

A vulnerability in Legion of the Bouncy Castle Inc. bc-csharp before version 2.7.0 causes a denial of service due to a loop with an unreachable exit condition in the Pkcs12Store.GetCertificateChain method. This occurs when processing crafted PKCS#12 files containing certificates whose issuer links form a cycle, leading to infinite looping and resource exhaustion until an OutOfMemoryException is thrown.

Join the discussion

A vulnerability in Legion of the Bouncy Castle Inc. bc-csharp before version 2.7.0 allows a remote attacker to recover the content-encryption key of a captured CMS EnvelopedData message. This is due to an observable discrepancy in the RSA PKCS#1 v1.5 key-transport unwrap process, where invalid padding errors are distinguishable from other decryption failures. This enables a Bleichenbacher-style adaptive chosen-ciphertext attack.

Join the discussion

An improper certificate validation vulnerability exists in the PkixNameConstraintValidator component of Legion of the Bouncy Castle Inc. bc-csharp before version 2.7.0. This flaw allows a name-constrained subordinate CA or an attacker with certificates containing chosen subjectAltName URIs to bypass URI name constraints during certification path validation. The issue arises because the host is extracted by string slicing without properly isolating the RFC 3986 authority component, causing the host compared against constraints to differ from the URI's actual host.

Join the discussion

CVE-2026-63569 is a critical vulnerability in the DHAgreement.CalculateAgreement method of the Legion of the Bouncy Castle Inc. bc-csharp library before version 2.7.0. It involves improper input validation in the MTI/A0 two-pass Diffie-Hellman key agreement, allowing an attacker to manipulate the agreed value and potentially recover the local static private key under certain conditions. This affects only applications that directly call DHAgreement.

Join the discussion

Inefficient algorithmic complexity in X.509 distinguished name string conversion (X509Name.ToString and IetfUtilities.ValueToString) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote unauthenticated attacker to cause a denial of service through CPU exhaustion via a certificate, CRL, certification request or other structure whose name contains a long attribute value made up of characters that must be escaped, such as commas, or of leading or trailing spaces, because each escaping backslash was inserted into the buffer being scanned, so the work grew quadratically with the length of the value. Applications are exposed when they convert such a name to a string, for example to log or display it, or compare it with IetfUtilities.RdnAreEqual, as PKIX path validation does for directoryName name constraints.

Join the discussion

Showing 1 to 10 of 17 results

Filters:Package: pkg:nuget/bc-csharp
Page 1 of 2
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses