PT-2026-95380 · Pypi · Rustls-Webpki

·

CVE-2026-93601

·

Published

2026-04-14

·

Updated

2026-10-02

CVSS v3.1

2.2

Low

VectorAV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions rustls-webpki versions 0.101.0 through 0.103.11 rustls-webpki versions 0.104.0-alpha.0 through 0.104.0-alpha.5
Description Permitted subtree DNS name constraints are incorrectly accepted for certificates asserting a wildcard name. For instance, a name constraint of accept.example.com could be satisfied by a certificate for *.example.com, which might include reject.example.com, a name outside the permitted subtree. This issue is only reachable after signature verification succeeds and requires a misissued wildcard certificate to exploit.
Recommendations Update rustls-webpki to version 0.103.12 or later. Update rustls-webpki to version 0.104.0-alpha.6 or later.

Exploit

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-103460
AZL-103500
AZL-103509
AZL-103521
CVE-2026-93601
GHSA-XGP8-3HG3-C2MH
OPENSUSE-SU-2026:11936-1
OPENSUSE-SU-2026:21982-1
OPENSUSE-SU-2026:22016-1
RUSTSEC-2026-0099

Affected Products

Rustls-Webpki