Skip to content

CVE 2026 103602

Peter Dettman edited this page Oct 1, 2026 · 1 revision

CVE-2026-103602

Issue affecting: BC C# .NET 2.6.2 and earlier, and the 2.7.0-beta.98 pre-release.

Fixed versions: BC C# .NET 2.7.0

Platform affected: All CLRs.

During certification path validation, PkixNameConstraintValidator checks the email addresses, DNS names and URIs in a certificate against the name constraints of the CA certificates above it. A host name may end with a dot that stands for the DNS root, so "example.com." and "example.com" name the same host. Earlier versions compared names with constraints without removing that dot. A trailing dot on the host of an rfc822Name, dNSName or uniformResourceIdentifier subject alternative name, or of an email address in the subject name, therefore stopped the name from matching a constraint for the same host. Permitted subtrees failed safe and rejected such a name, but an excluded subtree did not catch it.

Applications are exposed if they validate certificate paths with PkixCertPathValidator or PkixCertPathBuilder and rely on excluded subtrees to stop a CA, or a CA below it, from certifying particular email domains, DNS names or URI hosts. The operator of such a CA, or anyone who can get it to issue certificates with chosen names, could have a certificate accepted for a name inside an excluded subtree. This works wherever the application treats the name with the trailing dot as the same identity, as DNS resolution does. Constraints on directory names and IP addresses are not affected by this issue.

BC C# .NET 2.7.0 removes a single trailing dot from these names, and from constraints of the same types, before comparing them. A host that still ends with a dot after that, or contains any other empty label, is rejected whenever constraints of that type are in force. Names with one trailing dot inside a permitted subtree, which earlier versions rejected, are now accepted. No configuration is needed and there is no setting to bring back the old behaviour.

Users of earlier versions are advised to upgrade. Where that is not immediately possible, an application that relies on excluded subtrees for these name types can check the certificates of a validated path itself. It can reject any email address, DNS name or URI host that ends with a dot, or remove the dot and compare the name against the excluded subtrees of the CA certificates in the path.

The corresponding issue in BC Java was fixed in BC Java 1.85 (CVE-2026-8763).

Fix Commits:

Credit: Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research.

Clone this wiki locally