Improper certificate validation in the directoryName name-constraint check ...
zetlyn/cve-ghsa vulnerability ghsa GHSA-437r-hr8h-5f45 cve CVE-2026-63577 known 2026-10-02
https://github.com/advisories/GHSA-437r-hr8h-5f45
Properties
| cwe | CWE-295receipt
What the source handed over{
"credits": [],
"cve_id": "CVE-2026-63577",
"cvss": {
"score": null,
"vector_string": null
},
"cvss_severities": {
"cvss_v3": {
"score": 0.0,
"vector_string": null
},
"cvss_v4": {
"score": 8.2,
"vector_string": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
},
"cwes": [
{
"cwe_id": "CWE-295",
"name": "Improper Certificate Validation"
}
],
"description": "Improper certificate validation in the directoryName name-constraint check (PkixNameConstraintValidator.WithinDNSubtree) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who controls, or can have certificates issued by, a name-constrained intermediate CA to get certificates accepted by PKIX path validation whose subject distinguished name, or a directoryName subjectAltName, lies outside the CA's permitted subtrees, via a name that places other RDNs ahead of a copy of the permitted RDN sequence, because the check looks for the constraint's first RDN anywhere in the name and compares the remaining RDNs from that position, instead of requiring the constraint to be an initial prefix of the name as RFC 5280 sections 4.2.1.10 and 7.1 require.",
"ghsa_id": "GHSA-437r-hr8h-5f45",
"github_reviewed_at": null,
"html_url": "https://github.com/advisories/GHSA-437r-hr8h-5f45",
"identifiers": [
{
"type": "GHSA",
"value": "GHSA-437r-hr8h-5f45"
},
{
"type": "CVE",
"value": "CVE-2026-63577"
}
],
"nvd_published_at": "2026-10-02T08:17:02Z",
"published_at": "2026-10-02T09:31:20Z",
"references": [
"https://nvd.nist.gov/vuln/detail/CVE-2026-63577",
"https://github.com/bcgit/bc-csharp/commit/606e9153b97a265c70ca8293d21ec859344d7de8",
"https://github.com/bcgit/bc-csharp/commit/75c3c576602886180ed92a63c89419e3bd63b392",
"https://github.com/bcgit/bc-csharp/wiki/CVE-2026-63577",
"https://github.com/advisories/GHSA-437r-hr8h-5f45"
],
"repository_advisory_url": null,
"severity": "high",
"source_code_location": "",
"summary": "Improper certificate validation in the directoryName name-constraint check ...",
"type": "unreviewed",
"updated_at": "2026-10-02T09:31:30Z",
"url": "https://api.github.com/advisories/GHSA-437r-hr8h-5f45",
"vulnerabilities": [],
"withdrawn_at": null
} |
|---|---|
| severity | high From 7.0 to 8.9. receipt
What the source handed over{
"credits": [],
"cve_id": "CVE-2026-63577",
"cvss": {
"score": null,
"vector_string": null
},
"cvss_severities": {
"cvss_v3": {
"score": 0.0,
"vector_string": null
},
"cvss_v4": {
"score": 8.2,
"vector_string": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
},
"cwes": [
{
"cwe_id": "CWE-295",
"name": "Improper Certificate Validation"
}
],
"description": "Improper certificate validation in the directoryName name-constraint check (PkixNameConstraintValidator.WithinDNSubtree) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who controls, or can have certificates issued by, a name-constrained intermediate CA to get certificates accepted by PKIX path validation whose subject distinguished name, or a directoryName subjectAltName, lies outside the CA's permitted subtrees, via a name that places other RDNs ahead of a copy of the permitted RDN sequence, because the check looks for the constraint's first RDN anywhere in the name and compares the remaining RDNs from that position, instead of requiring the constraint to be an initial prefix of the name as RFC 5280 sections 4.2.1.10 and 7.1 require.",
"ghsa_id": "GHSA-437r-hr8h-5f45",
"github_reviewed_at": null,
"html_url": "https://github.com/advisories/GHSA-437r-hr8h-5f45",
"identifiers": [
{
"type": "GHSA",
"value": "GHSA-437r-hr8h-5f45"
},
{
"type": "CVE",
"value": "CVE-2026-63577"
}
],
"nvd_published_at": "2026-10-02T08:17:02Z",
"published_at": "2026-10-02T09:31:20Z",
"references": [
"https://nvd.nist.gov/vuln/detail/CVE-2026-63577",
"https://github.com/bcgit/bc-csharp/commit/606e9153b97a265c70ca8293d21ec859344d7de8",
"https://github.com/bcgit/bc-csharp/commit/75c3c576602886180ed92a63c89419e3bd63b392",
"https://github.com/bcgit/bc-csharp/wiki/CVE-2026-63577",
"https://github.com/advisories/GHSA-437r-hr8h-5f45"
],
"repository_advisory_url": null,
"severity": "high",
"source_code_location": "",
"summary": "Improper certificate validation in the directoryName name-constraint check ...",
"type": "unreviewed",
"updated_at": "2026-10-02T09:31:30Z",
"url": "https://api.github.com/advisories/GHSA-437r-hr8h-5f45",
"vulnerabilities": [],
"withdrawn_at": null
} |
Text
Improper certificate validation in the directoryName name-constraint check ...
Improper certificate validation in the directoryName name-constraint check (PkixNameConstraintValidator.WithinDNSubtree) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who controls, or can have certificates issued by, a name-constrained intermediate CA to get certificates accepted by PKIX path validation whose subject distinguished name, or a directoryName subjectAltName, lies outside the CA's permitted subtrees, via a name that places other RDNs ahead of a copy of the permitted RDN sequence, because the check looks for the constraint's first RDN anywhere in the name and compares the remaining RDNs from that position, instead of requiring the constraint to be an initial prefix of the name as RFC 5280 sections 4.2.1.10 and 7.1 require.