-
Notifications
You must be signed in to change notification settings - Fork 606
CVE 2026 63576
Issue affecting: BC C# .NET 2.6.2 and earlier, and the 2.7.0-beta.98 pre-release.
Fixed versions: BC C# .NET 2.7.0
Platform affected: All CLRs.
During certification path validation, PkixNameConstraintValidator checks uniformResourceIdentifier names in a certificate's subject alternative names against the URI name constraints of the CA certificates above it. RFC 5280 applies those constraints to the host part of the URI. The validator worked out that host by cutting the string at fixed characters, in an order that did not first separate the URI's authority from its path, query and fragment. In some URIs it therefore picked up text that is not the host at all: an '@' or ':' in the userinfo, path, query or fragment could make it compare a different host with the constraints. As a result a certificate could pass the permitted subtrees while naming a host outside them, or avoid an excluded subtree while naming a host inside it.
This matters only for applications that validate certification paths with Bouncy Castle (PkixCertPathValidator, PkixCertPathBuilder, or PkixNameConstraintValidator used directly) and trust a CA certificate that carries URI name constraints, and only when those constraints are the control the application relies on to limit which URI identities that CA, or a CA below it, can certify. Exploiting it needs a certificate from such a constrained CA with a URI chosen by the attacker, so the main threat is a constrained subordinate CA that misbehaves or is compromised. The other checks made by path validation are not affected.
BC C# .NET 2.7.0 parses the host following the URI authority structure of RFC 3986. The authority ends at the first '/', '?' or '#', userinfo is removed up to the last '@', a bracketed IPv6 literal is taken as it stands, and only then is a port removed. A host with an empty label is now rejected. No configuration is needed and there is no setting to bring back the old behaviour.
Users of earlier versions are advised to upgrade. Where that is not immediately possible, an application whose trust depends on URI name constraints can check the uniformResourceIdentifier names of a validated path itself. It should parse each name with a standards-compliant URI parser such as System.Uri, check that host against the URI name constraints of the CA certificates in the path, and reject names that do not parse. Rejecting URI names that contain '@' is not enough on its own.
Fix Commits:
Credit: Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research.