
The very first bug my .NET fuzzing found is finally public: a 75-byte PFX file that keeps BouncyCastle's Pkcs12Store.Load spinning for minutes. Fixed in 2.7.0. https://github.com/bcgit/bc-csharp/wiki/CVE-2026-63575 💪
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
Loop with unreachable exit condition in the PKCS#12 key derivation (Pkcs12ParametersGenerator) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who can supply a PKCS#12 (PFX) file, or a PKCS#8 encrypted private key that uses a PKCS#12 password-based encryption algorithm, to cause a denial of service through CPU exhaustion via an iteration count of zero or below, because the derivation loop ran until its counter equalled the count, so for such a count it wrapped through about 2^32 iterations before the MAC or the password could be checked. A 75-byte PFX file with a negative MacData iteration count kept Pkcs12Store.Load busy for many minutes.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
NONE
Momentum
NONE

The very first bug my .NET fuzzing found is finally public: a 75-byte PFX file that keeps BouncyCastle's Pkcs12Store.Load spinning for minutes. Fixed in 2.7.0. https://github.com/bcgit/bc-csharp/wiki/CVE-2026-63575 💪