Bouncy Castle: 25 Crypto Vulnerabilities Disclosed Together in Java and C# Libraries
Legion of the Bouncy Castle Inc. disclosed 25 vulnerabilities across its Java and C# libraries, impacting cryptographic functions and certificate validation.

Key findings
- 25 vulnerabilities disclosed together in Bouncy Castle Java and C# libraries, affecting versions prior to 1.86 and 2.7.0 respectively.
- Issues include improper handling of iteration counts in key derivation, leading to potential DoS.
- Certificate validation flaws in bc-csharp allow bypass of name constraints and acceptance of forged certificates.
- MLS implementation vulnerabilities in Java library could lead to impersonation or incorrect message processing.
- Side-channel leaks and inefficient algorithms identified in Java library's HQC and NTRU implementations.
- Urgent patching to versions 1.86 (Java) and 2.7.0 (C#) is recommended to address these critical and high-severity flaws.
On October 2nd and 3rd, 2026, a significant batch of 25 vulnerabilities was disclosed across Legion of the Bouncy Castle Inc.'s Java and C# libraries. These vulnerabilities, affecting versions prior to Bouncy Castle for Java 1.86 and bc-csharp 2.7.0, span a range of cryptographic functions, including key derivation, certificate validation, and message parsing. The disclosures highlight potential weaknesses in how the libraries handle untrusted input, resource allocation, and cryptographic signature verification, with several critical and high-severity issues identified.
Several vulnerabilities stem from improper handling of iteration counts in password-based key derivation functions. CVE-2026-97873 and CVE-2026-17508 in the Java library, and CVE-2026-63578 and CVE-2026-63572 in the C# library, allow attackers to dictate an arbitrary amount of work by providing small inputs, potentially leading to denial of service or prolonged processing times.
Certificate validation appears to be another area of concern. CVE-2026-63574 and CVE-2026-63576 in bc-csharp improperly validate name constraints, allowing attackers to bypass restrictions and potentially have forged certificates accepted. Similarly, CVE-2026-63571 in bc-csharp could lead to denial of service due to a loop with an unreachable exit condition in attribute certificate path validation. The Java library's CVE-2026-71889 also fails to apply X.509 name constraints correctly to end-entity certificates.
Messaging Layer Security (MLS) implementations are also affected. CVE-2026-71890 in the Java library fails to ensure that removed MLS leaves are associated with the joiner, and CVE-2026-71885, a critical vulnerability, does not bind an X.509 credential to an MLS LeafNode's signature key, potentially allowing for impersonation. CVE-2026-17507 in the Java library also presents an issue with MLS, where a signed integer is used for a field that should be unsigned, leading to incorrect decoding of legitimate wire values.
Other notable vulnerabilities include issues with OpenPGP parsing and validation. CVE-2026-85515 in the Java library accepts truncated OpenPGP messages without proper integrity checks. CVE-2026-71887 in the Java library mishandles authenticated attributes in CMS AuthenticatedData, and CVE-2026-71888 allows OpenPGP certificates to be issued without proper certification authority. In bc-csharp, CVE-2026-63573 and CVE-2026-63577 relate to improper handling of OpenPGP signature and user attribute subpackets, and certificate validation respectively.
The batch also includes vulnerabilities related to side-channel attacks and inefficient algorithms. CVE-2026-18040 in the Java library leaks secret-derived data through side channels in its HQC implementation. CVE-2026-18036 in the Java library uses inefficient reductions in its NTRU implementation, leading to latency dependent on secret operands. Finally, CVE-2026-103604 in bc-csharp exhibits inefficient algorithmic complexity in X.509 distinguished name string conversion, potentially leading to denial of service.
The extensive nature of this batch, with 25 CVEs disclosed simultaneously, underscores the importance of updating to Bouncy Castle for Java 1.86 and bc-csharp 2.7.0. Users are advised to review the specific CVE details relevant to their implementation and apply the necessary patches to mitigate risks associated with improper cryptographic handling, resource exhaustion, and potential data leakage. The wide range of affected components suggests a thorough review of security configurations and dependencies is warranted.