{"id":"CVE-2026-103603","summary":"Unbounded HSS public key level count allows huge array allocation during signature verification","details":"Memory allocation with excessive size value in the HSS/LMS signature code (HssPublicKeyParameters, HssSignature) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote unauthenticated attacker who can supply both an HSS public key and a signature to cause a denial of service through memory exhaustion via a public key encoding with an excessive level count, because the level count L read when parsing an HSS public key was not checked against the RFC 8554 maximum of 8, and signature parsing then allocated an array of L - 1 entries before reading any further signature data. A single verification can commit up to about 17 GB of memory or fail with an OutOfMemoryException.","modified":"2026-10-04T02:46:17.472045319Z","published":"2026-10-02T07:10:34.017Z","database_specific":{"cna_assigner":"bcorg","cwe_ids":["CWE-789"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/103xxx/CVE-2026-103603.json"},"references":[{"type":"WEB","url":"https://www.nuget.org/packages/BouncyCastle.Cryptography"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/103xxx/CVE-2026-103603.json"},{"type":"ADVISORY","url":"https://github.com/bcgit/bc-csharp/wiki/CVE-2026-103603"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-103603"},{"type":"FIX","url":"https://github.com/bcgit/bc-csharp/commit/f47ad47c7b5745b53d3f9ac711a5a419a272a5d7"},{"type":"PACKAGE","url":"https://github.com/bcgit/bc-csharp"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/bcgit/bc-csharp","events":[{"introduced":"0"},{"fixed":"4007498b13582d90ee1eda5d9920c324428b98b3"},{"fixed":"f47ad47c7b5745b53d3f9ac711a5a419a272a5d7"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"2.7.0"}],"source":["DESCRIPTION","REFERENCES"]}}],"versions":["release-1.9.0","release-1.8.10","release-1.8.8","release-1.8.7","release-1.8.6","release-1.8.5","release-1.8.4","release-1.8.3","release-1.8.2","release-1.8.1","release-1.8.0","release-1.8.0-RC.3","release-1.8.0-RC.2","release-1.8.0-RC.1","release-1.8.0-beta.4","release-1.8.0-beta.3","release-1.8.0-beta.2","release-1.8.0-beta.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-103603.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}]}