Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Tynus3

#32672of 57,584
8.7Total CVSS
Vulnerabilities · 1
PT-2026-95378
8.7
2026-04-22
Unknown · Rustls-Webpki · CVE-2026-93599
**Name of the Vulnerable Software and Affected Versions** rustls-webpki versions 0.103.0 through 0.103.12 rustls-webpki versions 0.104.0-alpha through 0.104.0-alpha.6 **Description** A denial of service occurs due to a panic in the `bit string flags()` function within `src/der.rs`. The issue arises when the function processes a named-bit BIT STRING with content exactly `[0x00]` (zero padding bits and no data bytes), causing a subtraction underflow on an empty slice and a subsequent index-out-of-bounds panic. This condition is reachable via the `BorrowedCertRevocationList::from der()` and `OwnedCertRevocationList::from der()` public APIs when a Certificate Revocation List (CRL) contains an `issuingDistributionPoint` extension with a specifically crafted `onlySomeReasons` value. This panic can occur before the CRL signature is verified. Exploitation requires an application to explicitly enable CRL revocation checking by passing `RevocationOptions` to the `verify for usage()` function and parsing CRL bytes from an attacker-controlled source. The default configuration does not use `RevocationOptions` and is therefore not affected. **Recommendations** Update rustls-webpki versions 0.103.0 through 0.103.12 to version 0.103.13. Update rustls-webpki versions 0.104.0-alpha through 0.104.0-alpha.6 to version 0.104.0-alpha.7.