PT-2024-17492 · Idna+5 · Idna+5

CVE-2024-12224

·

Published

2024-01-01

·

Updated

2026-07-30

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions idna versions 0.5.0 and earlier url versions prior to 2.5.4
Description The issue is related to improper validation of unsafe equivalence in punycode by the idna crate from Servo rust-url. This allows an attacker to create a punycode hostname that one part of a system might treat as distinct while another part of that system would treat as equivalent to another hostname. In applications using idna, this may lead to privilege escalation when host name comparison is part of a privilege check. The issue resulted from idna 0.5.0 and earlier implementing the UTS 46 specification literally on this point and the specification having this bug.
Recommendations Upgrade to idna 1.0.3 or later, if depending on idna directly. Upgrade to url 2.5.4 or later, if depending on idna via url. When upgrading, please take a moment to read about alternative Unicode back ends for idna. If you are using Rust earlier than 1.81 in combination with SQLx 0.8.2 or earlier, please also read an issue about combining them with url 2.5.4 and idna 1.0.3.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-13518
CVE-2024-12224
GHSA-H97M-WW89-6JMQ
OESA-2026-2944
OESA-2026-2945
OESA-2026-2946
OESA-2026-3013
OPENSUSE-SU-2025:15201-1
OPENSUSE-SU-2025:15202-1
OPENSUSE-SU-2025:15294-1
OPENSUSE-SU-2025:15353-1
OPENSUSE-SU-2025:15550-1
OPENSUSE-SU-2025:15551-1
OPENSUSE-SU-2025:15588-1
OPENSUSE-SU-2025:15656-1
OPENSUSE-SU-2026:20060-1
OPENSUSE-SU-2026:20396-1
RHSA-2025:16108
RHSA-2025:16109
RHSA-2025:16156
RHSA-2025:16157
RHSA-2025:16260
RHSA-2025:16589
RHSA-2025:17340
RHSA-2025:17341
RHSA-2025:17342
RHSA-2025:17343
RHSA-2025:17344
RHSA-2025:17345
RHSA-2025:17346
RHSA-2025:17367
RHSA-2025:17368
RHSA-2025:17371
RHSA-2025:17372
RHSA-2025:17373
RHSA-2025:17374
RHSA-2025:17378
RHSA-2025:17453
RUSTSEC-2024-0421
SUSE-RU-2025:02203-1
SUSE-RU-2025:02204-1
SUSE-SU-2025:02586-1
SUSE-SU-2025:02587-1
SUSE-SU-2025:02768-1
SUSE-SU-2025:02809-1
SUSE-SU-2025:02810-1
SUSE-SU-2025:02811-1
SUSE-SU-2025:03298-1
SUSE-SU-2025:03306-1
SUSE-SU-2025:03307-1
SUSE-SU-2025:03445-1
SUSE-SU-2025:20491-1
SUSE-SU-2025:20716-1
SUSE-SU-2025:20783-1
SUSE-SU-2025:20858-1
SUSE-SU-2025:3783-1
SUSE-SU-2025:3784-1
SUSE-SU-2025:3785-1
SUSE-SU-2025:3786-1
SUSE-SU-2025:4411-1
SUSE-SU-2025_02586-1
SUSE-SU-2025_02768-1
SUSE-SU-2025_03298-1
SUSE-SU-2025_03306-1
SUSE-SU-2025_03307-1
SUSE-SU-2025_03445-1
SUSE-SU-2026:0243-1
SUSE-SU-2026:0620-1
SUSE-SU-2026:20096-1
SUSE-SU-2026:20755-1
SUSE-SU-2026:20910-1
SUSE-SU-2026:22917-1
SUSE-SU-2026:23071-1
SUSE-SU-2026:2831-1
SUSE-SU-2026:2832-1
SUSE-SU-2026:3022-1

Affected Products

Debian
Rust
Sqlx
Suse
Idna
Url