CVE-2026-63569
Nieprawidłowa walidacja wejścia w Bouncy Castle umożliwia atakującemu poznanie klucza prywatnego.
Improper input validation in DHAgreement.CalculateAgreement (MTI/A0 two-pass Diffie-Hellman) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an on-path attacker to make the local party compute an agreed value the attacker already knows, defeating the key authentication MTI/A0 is meant to provide. It also allows a malicious peer to learn the local static private key modulo the small factors of p-1, and to recover it entirely in groups with many such factors. The attack uses a crafted out-of-range or small-order ephemeral value, and works because that value is raised to the static private key without the range and subgroup-membership checks applied to DH public keys. Only applications that call DHAgreement directly are affected.
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 0.0 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.4% |
| Opublikowano (NVD) | 2026-10-02 07:16:37 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-02 19:16:41 UTC |
- https://github.com/bcgit/bc-csharp/commit/fe236ad207c5960eeae1ebb6560c783a3bb5b692 (91579145-5d7b-4cc5-b925-a0262ff19630)
- https://github.com/bcgit/bc-csharp/wiki/CVE-2026-63569 (91579145-5d7b-4cc5-b925-a0262ff19630)