OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-103603

HIGH · CVSS 8.7 EPSS 0.41% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-02 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

The vulnerability arises from improper memory allocation in the HSS/LMS signature code of Legion of the Bouncy Castle Inc. bc-csharp, allowing remote unauthenticated attackers to exploit excessive size values in public key encoding. This can lead to denial of service through memory exhaustion, potentially consuming up to 17 GB of memory during a single verification attempt. Organizations utilizing affected versions should prioritize patching to mitigate the risk of service disruption.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-103603
Severity
HIGH
CVSS
8.7
EPSS
0.41%

Original NVD Description

Memory allocation with excessive size value in the HSS/LMS signature code (HssPublicKeyParameters, HssSignature) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote unauthenticated attacker who can supply both an HSS public key and a signature to cause a denial of service through memory exhaustion via a public key encoding with an excessive level count, because the level count L read when parsing an HSS public key was not checked against the RFC 8554 maximum of 8, and signature parsing then allocated an array of L - 1 entries before reading any further signature data. A single verification can commit up to about 17 GB of memory or fail with an OutOfMemoryException.