OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-103600

HIGH · CVSS 8.7 EPSS 0.32% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-02 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

The vulnerability affects the ASN.1 parser in the Bouncy Castle library for .NET, allowing remote unauthenticated attackers to exploit uncontrolled recursion and trigger a denial of service by sending specially crafted ASN.1 encodings. This can lead to a StackOverflowException, terminating the process and impacting any application that parses untrusted ASN.1 data, such as X.509 certificates and TLS messages. Organizations using affected versions of the library should prioritize patching to mitigate potential service disruptions.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-103600
Severity
HIGH
CVSS
8.7
EPSS
0.32%
Windows

Original NVD Description

Uncontrolled recursion in the ASN.1 parser (Asn1InputStream, Asn1StreamParser) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote unauthenticated attacker to cause a denial of service via a crafted ASN.1 encoding of deeply nested constructed elements (for example SEQUENCE inside SEQUENCE, in definite-length DER or indefinite-length BER form), because each nesting level is parsed by a further recursive call with no bound on depth. About 2,000 levels (8 KB of DER) are enough to exhaust a 1.5 MB thread stack, the .NET main-thread default on Windows, and raise a StackOverflowException, which .NET cannot catch and which terminates the whole process; on threads with larger stacks, parse time instead grows quadratically with depth (about 9 seconds of CPU for a 64 KB input). Any path that parses untrusted ASN.1 is exposed, including X.509 certificates and CRLs, CMS/PKCS#7, PKCS#8/PKCS#12, OCSP and TLS Certificate messages.