PT-2026-95381 · Unknown · Rustls-Webpki

·

CVE-2026-93602

·

Published

2026-03-20

·

Updated

2026-10-02

CVSS v4.0

5.9

Medium

VectorAV:N/AC:H/AT:P/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions rustls-webpki versions prior to 0.103.10 rustls-webpki versions prior to 0.104.0-alpha.5
Description Faulty CRL (Certificate Revocation List) authority-matching logic occurs when a certificate contains multiple distributionPoint entries. The system only compares the first distributionPoint against each CRL's IssuingDistributionPoint, ignoring all subsequent entries. This results in correctly provided CRLs not being consulted for revocation checks. If UnknownStatusPolicy::Allow is used, revoked certificates may be inappropriately accepted. Under the default UnknownStatusPolicy::Deny policy, this leads to an incorrect Error::UnknownRevocationStatus. Exploitation requires a compromised trusted issuing authority to present revoked certificates or leverage the faulty checking to continue using revoked credentials.
Recommendations Update rustls-webpki to version 0.103.10 or later. Update rustls-webpki to version 0.104.0-alpha.5 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-103463
AZL-103503
AZL-103511
AZL-103524
CVE-2026-93602
GHSA-PWJX-QHCG-RVJ4
OPENSUSE-SU-2026:11936-1
OPENSUSE-SU-2026:21982-1
OPENSUSE-SU-2026:22016-1
RUSTSEC-2026-0049
SUSE-SU-2026:23983-1

Affected Products

Rustls-Webpki