Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 02 Oct 2026 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper certificate validation in PkixNameConstraintValidator in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who controls, or can obtain certificates from, a name-constrained intermediate CA to have certificates accepted during PKIX certification path validation for email addresses, DNS names or URI hosts that lie within excluded subtrees applying to that CA, via an rfc822Name, dNSName or uniformResourceIdentifier name whose host ends with a dot, because names and constraints were compared without first removing the RFC 1034 root-label trailing dot, so a fully qualified host name did not match an excluded subtree for the same host written without the dot. | |
| Title | Name constraints bypass via trailing dot in rfc822Name, dNSName and URI hosts | |
| Weaknesses | CWE-295 | |
| References |
|
|
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: bcorg
Published:
Updated: 2026-10-02T07:10:03.885Z
Reserved: 2026-09-30T23:01:10.053Z
Link: CVE-2026-103602
No data.
Status : Received
Published: 2026-10-02T08:17:00.677
Modified: 2026-10-02T08:17:00.677
Link: CVE-2026-103602
No data.
OpenCVE Enrichment
No data.
-
CWE-295
Improper Certificate Validation