OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-63575

HIGH · CVSS 7.1 EPSS 0.19% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-02 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

The vulnerability exists in the PKCS#12 key derivation process of the Bouncy Castle library, where an attacker can exploit a zero or negative iteration count in a provided PKCS#12 file or PKCS#8 encrypted private key, leading to a denial of service through excessive CPU consumption. This flaw can cause significant performance degradation, as the derivation loop may run for an extended period, effectively freezing the application. Organizations using affected versions of the Bouncy Castle library should prioritize patching to mitigate the risk of service disruption.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-63575
Severity
HIGH
CVSS
7.1
EPSS
0.19%

Original NVD Description

Loop with unreachable exit condition in the PKCS#12 key derivation (Pkcs12ParametersGenerator) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who can supply a PKCS#12 (PFX) file, or a PKCS#8 encrypted private key that uses a PKCS#12 password-based encryption algorithm, to cause a denial of service through CPU exhaustion via an iteration count of zero or below, because the derivation loop ran until its counter equalled the count, so for such a count it wrapped through about 2^32 iterations before the MAC or the password could be checked. A 75-byte PFX file with a negative MacData iteration count kept Pkcs12Store.Load busy for many minutes.