PT-2026-95378 · Unknown · Rustls-Webpki

·

CVE-2026-93599

·

Published

2026-04-22

·

Updated

2026-10-02

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions rustls-webpki versions 0.103.0 through 0.103.12 rustls-webpki versions 0.104.0-alpha through 0.104.0-alpha.6
Description A denial of service occurs due to a panic in the bit string flags() function within src/der.rs. The issue arises when the function processes a named-bit BIT STRING with content exactly [0x00] (zero padding bits and no data bytes), causing a subtraction underflow on an empty slice and a subsequent index-out-of-bounds panic. This condition is reachable via the BorrowedCertRevocationList::from der() and OwnedCertRevocationList::from der() public APIs when a Certificate Revocation List (CRL) contains an issuingDistributionPoint extension with a specifically crafted onlySomeReasons value. This panic can occur before the CRL signature is verified. Exploitation requires an application to explicitly enable CRL revocation checking by passing RevocationOptions to the verify for usage() function and parsing CRL bytes from an attacker-controlled source. The default configuration does not use RevocationOptions and is therefore not affected.
Recommendations Update rustls-webpki versions 0.103.0 through 0.103.12 to version 0.103.13. Update rustls-webpki versions 0.104.0-alpha through 0.104.0-alpha.6 to version 0.104.0-alpha.7.

Exploit

Fix

DoS

Out of bounds Read

Integer Underflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-103469
AZL-103494
AZL-103506
AZL-103518
CVE-2026-93599
GHSA-82J2-J2CH-GFR8
OPENSUSE-SU-2026:11861-1
OPENSUSE-SU-2026:11936-1
OPENSUSE-SU-2026:11976-1
OPENSUSE-SU-2026:21982-1
OPENSUSE-SU-2026:22016-1
RHSA-2026:42825
RHSA-2026:57200
RHSA-2026:66076
RUSTSEC-2026-0104

Affected Products

Rustls-Webpki