CVE-2026-63576
Nieprawidłowa walidacja certyfikatów w Bouncy Castle umożliwia obejście ograniczeń nazw w ścieżkach certyfikacji.
Improper certificate validation in PkixNameConstraintValidator (ExtractHostFromURL) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a name-constrained subordinate CA, or anyone able to obtain certificates with chosen subjectAltName URIs from such a CA, to bypass permitted or excluded uniformResourceIdentifier name constraints during certification path validation via a URI whose path, query, fragment or userinfo contains characters such as '@' or ':', because the host was extracted by string slicing without first isolating the RFC 3986 authority component, so the host compared against the constraints could differ from the URI's actual host.
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 0.0 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.2% |
| Opublikowano (NVD) | 2026-10-02 08:17:02 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-02 14:44:52 UTC |
- https://github.com/bcgit/bc-csharp/commit/f196a22bbf7765cc19b0c4f4645c74ea7ad35e09 (91579145-5d7b-4cc5-b925-a0262ff19630)
- https://github.com/bcgit/bc-csharp/wiki/CVE-2026-63576 (91579145-5d7b-4cc5-b925-a0262ff19630)