-
Notifications
You must be signed in to change notification settings - Fork 604
CVE 2026 63571
Issue affecting: BC C# .NET 2.6.2 and earlier, and the 2.7.0-beta.98 pre-release.
Fixed versions: BC C# .NET 2.7.0
Platform affected: All CLRs.
PkixAttrCertPathValidator validates an X.509 attribute certificate (RFC 3281) together with the certification path of its issuer, the attribute authority. PkixAttrCertPathBuilder uses it after building that path. Validation checks the holder's certification path, the issuer's certification path, that the issuer is one of the trusted attribute certificate issuers set in PkixParameters, the validity period, critical extensions, necessary and prohibited attributes and, if enabled, revocation status. It never checked the signature on the attribute certificate itself.
Nothing therefore tied the contents of an attribute certificate to the attribute authority named as its issuer. Anyone able to submit an attribute certificate to an application that uses these classes could make one up that names a trusted attribute authority as issuer, carries attributes of their choosing and has a signature that authority never produced, and it would be reported as valid. Applications that grant roles, clearances or other privileges on the strength of a validated attribute certificate are exposed to privilege escalation. No other part of the library uses these classes, so CMS, TLS, OCSP and ordinary certificate path validation with PkixCertPathValidator are not affected.
BC C# .NET 2.7.0 verifies the attribute certificate's signature with the public key of the first certificate in the issuer's certification path, as soon as that path has been validated. If the signature does not verify, validation fails with a PkixCertPathValidatorException. No configuration is needed.
Upgrading is recommended. Applications on earlier versions should verify the signature themselves by calling Verify, or IsSignatureValid, on the X509V2AttributeCertificate with the public key of the attribute authority's certificate (the first certificate in the path passed to Validate), and reject the attribute certificate on failure. The check can also run inside validation: register a PkixAttrCertChecker through PkixParameters.SetAttrCertCheckers. Its Check method receives both the attribute certificate and the issuer's certification path, and this route also covers PkixAttrCertPathBuilder.
Fix Commits:
Credit: Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research.