PT-2026-95379 · Pypi · Rustls-Webpki

·

CVE-2026-93600

·

Published

2026-04-14

·

Updated

2026-10-02

CVSS v3.1

2.2

Low

VectorAV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions rustls-webpki versions 0.101.0 through 0.103.11 rustls-webpki versions 0.104.0-alpha through 0.104.0-alpha.5
Description The software ignores X.509 name constraints that apply to URI names, causing these constraints to be accepted instead of enforced. This issue is only reachable after successful signature verification and requires a misissued certificate to exploit. The library does not provide an API for asserting URI names, and URI name constraints are otherwise unimplemented.
Recommendations Update to version 0.103.12. Update to version 0.104.0-alpha.6.

Exploit

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-103466
AZL-103496
AZL-103515
AZL-103527
CVE-2026-93600
GHSA-965H-392X-2MH5
OPENSUSE-SU-2026:11936-1
OPENSUSE-SU-2026:21982-1
OPENSUSE-SU-2026:22016-1
RUSTSEC-2026-0098

Affected Products

Rustls-Webpki