Improper certificate validation in the directoryName name-constraint check (PkixNameConstraintValidator.WithinDNSubtree) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who controls, or can have certificates issued by, a name-constrained intermediate CA to get certificates accepted by PKIX path validation whose subject distinguished name, or a directoryName subjectAltName, lies outside the CA's permitted subtrees, via a name that places other RDNs ahead of a copy of the permitted RDN sequence, because the check looks for the constraint's first RDN anywhere in the name and compares the remaining RDNs from that position, instead of requiring the constraint to be an initial prefix of the name as RFC 5280 sections 4.2.1.10 and 7.1 require.

cve CVE-2026-63577 2 sources, 2 claims · Watch

NVD writes:
Improper certificate validation in the directoryName name-constraint check (PkixNameConstraintValidator.WithinDNSubtree) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who controls, or can have certificates issued by, a name-constrained intermediate CA to get certificates accepted by PKIX path validation whose subject distinguished name, or a directoryName subjectAltName, lies outside the CA's permitted subtrees, via a name that places other RDNs ahead of a copy of the permitted RDN sequence, because the check looks for the constraint's first RDN anywhere in the … the claim

What it is to other things

In words only, so not counted until a person confirms one:

affectslegion_of_the_bouncy_castle_inc/bc_csharp
NVD says “Legion of the Bouncy Castle Inc. · bc-csharp”
made_bylegion_of_the_bouncy_castle_inc
NVD says “Legion of the Bouncy Castle Inc.”

What each source says

PropertySourceSaidMeans here
Cwe
cwe
GitHub advisoriesCWE-295
receipt
Source
GitHub advisories
Its words
CWE-295
Read by
field:cwes[].cwe_id
Said since
2026-10-02 11:59 UTC
Last answered
2026-10-04 18:15 UTC
Original
open at the source
What the source handed over
{
  "credits": [],
  "cve_id": "CVE-2026-63577",
  "cvss": {
    "score": null,
    "vector_string": null
  },
  "cvss_severities": {
    "cvss_v3": {
      "score": 0.0,
      "vector_string": null
    },
    "cvss_v4": {
      "score": 8.2,
      "vector_string": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
    }
  },
  "cwes": [
    {
      "cwe_id": "CWE-295",
      "name": "Improper Certificate Validation"
    }
  ],
  "description": "Improper certificate validation in the directoryName name-constraint check (PkixNameConstraintValidator.WithinDNSubtree) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who controls, or can have certificates issued by, a name-constrained intermediate CA to get certificates accepted by PKIX path validation whose subject distinguished name, or a directoryName subjectAltName, lies outside the CA's permitted subtrees, via a name that places other RDNs ahead of a copy of the permitted RDN sequence, because the check looks for the constraint's first RDN anywhere in the name and compares the remaining RDNs from that position, instead of requiring the constraint to be an initial prefix of the name as RFC 5280 sections 4.2.1.10 and 7.1 require.",
  "ghsa_id": "GHSA-437r-hr8h-5f45",
  "github_reviewed_at": null,
  "html_url": "https://github.com/advisories/GHSA-437r-hr8h-5f45",
  "identifiers": [
    {
      "type": "GHSA",
      "value": "GHSA-437r-hr8h-5f45"
    },
    {
      "type": "CVE",
      "value": "CVE-2026-63577"
    }
  ],
  "nvd_published_at": "2026-10-02T08:17:02Z",
  "published_at": "2026-10-02T09:31:20Z",
  "references": [
    "https://nvd.nist.gov/vuln/detail/CVE-2026-63577",
    "https://github.com/bcgit/bc-csharp/commit/606e9153b97a265c70ca8293d21ec859344d7de8",
    "https://github.com/bcgit/bc-csharp/commit/75c3c576602886180ed92a63c89419e3bd63b392",
    "https://github.com/bcgit/bc-csharp/wiki/CVE-2026-63577",
    "https://github.com/advisories/GHSA-437r-hr8h-5f45"
  ],
  "repository_advisory_url": null,
  "severity": "high",
  "source_code_location": "",
  "summary": "Improper certificate validation in the directoryName name-constraint check ...",
  "type": "unreviewed",
  "updated_at": "2026-10-02T09:31:30Z",
  "url": "https://api.github.com/advisories/GHSA-437r-hr8h-5f45",
  "vulnerabilities": [],
  "withdrawn_at": null
}
—
Product
product
NVDbc-csharp
receipt
Source
NVD
Its words
bc-csharp
Read by
field:cve.affected[].affectedData[].product
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-04 18:16 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "collectionURL": "https://www.nuget.org/packages/BouncyCastle.Cryptography",
            "defaultStatus": "unaffected",
            "packageName": "BouncyCastle.Cryptography",
            "product": "bc-csharp",
            "programFiles": [
              "crypto/src/pkix/PkixNameConstraintValidator.cs"
            ],
            "repo": "https://github.com/bcgit/bc-csharp",
            "vendor": "Legion of the Bouncy Castle Inc.",
            "versions": [
              {
                "lessThan": "2.7.0",
                "status": "affected",
                "version": "0",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "91579145-5d7b-4cc5-b925-a0262ff19630"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Improper certificate validation in the directoryName name-constraint check (PkixNameConstraintValidator.WithinDNSubtree) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who controls, or can have certificates issued by, a name-constrained intermediate CA to get certificates accepted by PKIX path validation whose subject distinguished name, or a directoryName subjectAltName, lies outside the CA's permitted subtrees, via a name that places other RDNs ahead of a copy of the permitted RDN sequence, because the check looks for the constraint's first RDN anywhere in the name and compares the remaining RDNs from that position, instead of requiring the constraint to be an initial prefix of the name as RFC 5280 sections 4.2.1.10 and 7.1 require."
      }
    ],
    "id": "CVE-2026-63577",
    "lastModified": "2026-10-02T14:44:52.247",
    "metrics": {
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "PRESENT",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "NONE",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "NONE",
            "vulnIntegrityImpact": "HIGH",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "91579145-5d7b-4cc5-b925-a0262ff19630",
          "type": "Secondary"
        }
      ]
    },
    "published": "2026-10-02T08:17:02.937",
    "references": [
      {
        "source": "91579145-5d7b-4cc5-b925-a0262ff19630",
        "url": "https://github.com/bcgit/bc-csharp/commit/606e9153b97a265c70ca8293d21ec859344d7de8"
      },
      {
        "source": "91579145-5d7b-4cc5-b925-a0262ff19630",
        "url": "https://github.com/bcgit/bc-csharp/commit/75c3c576602886180ed92a63c89419e3bd63b392"
      },
      {
        "source": "91579145-5d7b-4cc5-b925-a0262ff19630",
        "url": "https://github.com/bcgit/bc-csharp/wiki/CVE-2026-63577"
      }
    ],
    "sourceIdentifier": "91579145-5d7b-4cc5-b925-a0262ff19630",
    "vulnStatus": "Undergoing Analysis",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-295"
          }
        ],
        "source": "91579145-5d7b-4cc5-b925-a0262ff19630",
        "type": "Secondary"
      }
    ]
  }
}
—
Severity
severity
GitHub advisorieshigh
From 7.0 to 8.9.
receipt
Source
GitHub advisories
Its words
high
Read by
field:severity
Said since
2026-10-02 11:59 UTC
Last answered
2026-10-04 18:15 UTC
Original
open at the source
What the source handed over
{
  "credits": [],
  "cve_id": "CVE-2026-63577",
  "cvss": {
    "score": null,
    "vector_string": null
  },
  "cvss_severities": {
    "cvss_v3": {
      "score": 0.0,
      "vector_string": null
    },
    "cvss_v4": {
      "score": 8.2,
      "vector_string": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
    }
  },
  "cwes": [
    {
      "cwe_id": "CWE-295",
      "name": "Improper Certificate Validation"
    }
  ],
  "description": "Improper certificate validation in the directoryName name-constraint check (PkixNameConstraintValidator.WithinDNSubtree) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who controls, or can have certificates issued by, a name-constrained intermediate CA to get certificates accepted by PKIX path validation whose subject distinguished name, or a directoryName subjectAltName, lies outside the CA's permitted subtrees, via a name that places other RDNs ahead of a copy of the permitted RDN sequence, because the check looks for the constraint's first RDN anywhere in the name and compares the remaining RDNs from that position, instead of requiring the constraint to be an initial prefix of the name as RFC 5280 sections 4.2.1.10 and 7.1 require.",
  "ghsa_id": "GHSA-437r-hr8h-5f45",
  "github_reviewed_at": null,
  "html_url": "https://github.com/advisories/GHSA-437r-hr8h-5f45",
  "identifiers": [
    {
      "type": "GHSA",
      "value": "GHSA-437r-hr8h-5f45"
    },
    {
      "type": "CVE",
      "value": "CVE-2026-63577"
    }
  ],
  "nvd_published_at": "2026-10-02T08:17:02Z",
  "published_at": "2026-10-02T09:31:20Z",
  "references": [
    "https://nvd.nist.gov/vuln/detail/CVE-2026-63577",
    "https://github.com/bcgit/bc-csharp/commit/606e9153b97a265c70ca8293d21ec859344d7de8",
    "https://github.com/bcgit/bc-csharp/commit/75c3c576602886180ed92a63c89419e3bd63b392",
    "https://github.com/bcgit/bc-csharp/wiki/CVE-2026-63577",
    "https://github.com/advisories/GHSA-437r-hr8h-5f45"
  ],
  "repository_advisory_url": null,
  "severity": "high",
  "source_code_location": "",
  "summary": "Improper certificate validation in the directoryName name-constraint check ...",
  "type": "unreviewed",
  "updated_at": "2026-10-02T09:31:30Z",
  "url": "https://api.github.com/advisories/GHSA-437r-hr8h-5f45",
  "vulnerabilities": [],
  "withdrawn_at": null
}
—
Status
status
NVDUndergoing Analysis
receipt
Source
NVD
Its words
Undergoing Analysis
Read by
field:cve.vulnStatus
Said since
2026-10-03 00:06 UTC
Last answered
2026-10-04 18:16 UTC
Original
open at the source
2026-10-03 00:06 UTCUndergoing Analysis
2026-10-02 18:03 UTCAwaiting Analysis
2026-10-02 12:00 UTCReceived
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "collectionURL": "https://www.nuget.org/packages/BouncyCastle.Cryptography",
            "defaultStatus": "unaffected",
            "packageName": "BouncyCastle.Cryptography",
            "product": "bc-csharp",
            "programFiles": [
              "crypto/src/pkix/PkixNameConstraintValidator.cs"
            ],
            "repo": "https://github.com/bcgit/bc-csharp",
            "vendor": "Legion of the Bouncy Castle Inc.",
            "versions": [
              {
                "lessThan": "2.7.0",
                "status": "affected",
                "version": "0",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "91579145-5d7b-4cc5-b925-a0262ff19630"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Improper certificate validation in the directoryName name-constraint check (PkixNameConstraintValidator.WithinDNSubtree) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who controls, or can have certificates issued by, a name-constrained intermediate CA to get certificates accepted by PKIX path validation whose subject distinguished name, or a directoryName subjectAltName, lies outside the CA's permitted subtrees, via a name that places other RDNs ahead of a copy of the permitted RDN sequence, because the check looks for the constraint's first RDN anywhere in the name and compares the remaining RDNs from that position, instead of requiring the constraint to be an initial prefix of the name as RFC 5280 sections 4.2.1.10 and 7.1 require."
      }
    ],
    "id": "CVE-2026-63577",
    "lastModified": "2026-10-02T14:44:52.247",
    "metrics": {
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "PRESENT",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "NONE",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "NONE",
            "vulnIntegrityImpact": "HIGH",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "91579145-5d7b-4cc5-b925-a0262ff19630",
          "type": "Secondary"
        }
      ]
    },
    "published": "2026-10-02T08:17:02.937",
    "references": [
      {
        "source": "91579145-5d7b-4cc5-b925-a0262ff19630",
        "url": "https://github.com/bcgit/bc-csharp/commit/606e9153b97a265c70ca8293d21ec859344d7de8"
      },
      {
        "source": "91579145-5d7b-4cc5-b925-a0262ff19630",
        "url": "https://github.com/bcgit/bc-csharp/commit/75c3c576602886180ed92a63c89419e3bd63b392"
      },
      {
        "source": "91579145-5d7b-4cc5-b925-a0262ff19630",
        "url": "https://github.com/bcgit/bc-csharp/wiki/CVE-2026-63577"
      }
    ],
    "sourceIdentifier": "91579145-5d7b-4cc5-b925-a0262ff19630",
    "vulnStatus": "Undergoing Analysis",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-295"
          }
        ],
        "source": "91579145-5d7b-4cc5-b925-a0262ff19630",
        "type": "Secondary"
      }
    ]
  }
}
—
Vendor
vendor
NVDLegion of the Bouncy Castle Inc.
receipt
Source
NVD
Its words
Legion of the Bouncy Castle Inc.
Read by
field:cve.affected[].affectedData[].vendor
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-04 18:16 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "collectionURL": "https://www.nuget.org/packages/BouncyCastle.Cryptography",
            "defaultStatus": "unaffected",
            "packageName": "BouncyCastle.Cryptography",
            "product": "bc-csharp",
            "programFiles": [
              "crypto/src/pkix/PkixNameConstraintValidator.cs"
            ],
            "repo": "https://github.com/bcgit/bc-csharp",
            "vendor": "Legion of the Bouncy Castle Inc.",
            "versions": [
              {
                "lessThan": "2.7.0",
                "status": "affected",
                "version": "0",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "91579145-5d7b-4cc5-b925-a0262ff19630"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Improper certificate validation in the directoryName name-constraint check (PkixNameConstraintValidator.WithinDNSubtree) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who controls, or can have certificates issued by, a name-constrained intermediate CA to get certificates accepted by PKIX path validation whose subject distinguished name, or a directoryName subjectAltName, lies outside the CA's permitted subtrees, via a name that places other RDNs ahead of a copy of the permitted RDN sequence, because the check looks for the constraint's first RDN anywhere in the name and compares the remaining RDNs from that position, instead of requiring the constraint to be an initial prefix of the name as RFC 5280 sections 4.2.1.10 and 7.1 require."
      }
    ],
    "id": "CVE-2026-63577",
    "lastModified": "2026-10-02T14:44:52.247",
    "metrics": {
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "PRESENT",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "NONE",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "NONE",
            "vulnIntegrityImpact": "HIGH",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "91579145-5d7b-4cc5-b925-a0262ff19630",
          "type": "Secondary"
        }
      ]
    },
    "published": "2026-10-02T08:17:02.937",
    "references": [
      {
        "source": "91579145-5d7b-4cc5-b925-a0262ff19630",
        "url": "https://github.com/bcgit/bc-csharp/commit/606e9153b97a265c70ca8293d21ec859344d7de8"
      },
      {
        "source": "91579145-5d7b-4cc5-b925-a0262ff19630",
        "url": "https://github.com/bcgit/bc-csharp/commit/75c3c576602886180ed92a63c89419e3bd63b392"
      },
      {
        "source": "91579145-5d7b-4cc5-b925-a0262ff19630",
        "url": "https://github.com/bcgit/bc-csharp/wiki/CVE-2026-63577"
      }
    ],
    "sourceIdentifier": "91579145-5d7b-4cc5-b925-a0262ff19630",
    "vulnStatus": "Undergoing Analysis",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-295"
          }
        ],
        "source": "91579145-5d7b-4cc5-b925-a0262ff19630",
        "type": "Secondary"
      }
    ]
  }
}
—

vulnerability

Improper certificate validation in the directoryName name-constraint check (PkixNameConstraintValidator.WithinDNSubtree) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who controls, or can have certificates issued by, a name-constrained intermediate CA to get certificates accepted by PKIX path validation whose subject distinguished name, or a directoryName subjectAltName, lies outside the CA's permitted subtrees, via a name that places other RDNs ahead of a copy of the permitted RDN sequence, because the check looks for the constraint's first RDN anywhere in the name and compares the remaining RDNs from that position, instead of requiring the constraint to be an initial prefix of the name as RFC 5280 sections 4.2.1.10 and 7.1 require.
zetlyn/cve-nvd · 2026-10-02
product bc-csharp status Undergoing Analysis vendor Legion of the Bouncy Castle Inc. source
Improper certificate validation in the directoryName name-constraint check ...
zetlyn/cve-ghsa · 2026-10-02
cwe CWE-295 severity high source