OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-63569

CRITICAL · CVSS 9.1 EPSS 0.40% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-02 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

Improper input validation in the DHAgreement.CalculateAgreement function of the Bouncy Castle library allows an on-path attacker to manipulate the Diffie-Hellman key exchange process, potentially exposing the local party's static private key and undermining key authentication. This vulnerability can lead to unauthorized access and data breaches, making it critical for developers and organizations using this library, particularly those implementing cryptographic protocols, to prioritize immediate remediation. Users should upgrade to version 2.7.0 or later to mitigate these risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-63569
Severity
CRITICAL
CVSS
9.1
EPSS
0.40%

Original NVD Description

Improper input validation in DHAgreement.CalculateAgreement (MTI/A0 two-pass Diffie-Hellman) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an on-path attacker to make the local party compute an agreed value the attacker already knows, defeating the key authentication MTI/A0 is meant to provide. It also allows a malicious peer to learn the local static private key modulo the small factors of p-1, and to recover it entirely in groups with many such factors. The attack uses a crafted out-of-range or small-order ephemeral value, and works because that value is raised to the static private key without the range and subgroup-membership checks applied to DH public keys. Only applications that call DHAgreement directly are affected.