PT-2026-95380 · Pypi · Rustls-Webpki
CVSS v3.1
2.2
Low
| Vector | AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
rustls-webpki versions 0.101.0 through 0.103.11
rustls-webpki versions 0.104.0-alpha.0 through 0.104.0-alpha.5
Description
Permitted subtree DNS name constraints are incorrectly accepted for certificates asserting a wildcard name. For instance, a name constraint of
accept.example.com could be satisfied by a certificate for *.example.com, which might include reject.example.com, a name outside the permitted subtree. This issue is only reachable after signature verification succeeds and requires a misissued wildcard certificate to exploit.Recommendations
Update rustls-webpki to version 0.103.12 or later.
Update rustls-webpki to version 0.104.0-alpha.6 or later.
Exploit
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rustls-Webpki