PT-2026-95381 · Unknown · Rustls-Webpki
CVSS v4.0
5.9
Medium
| Vector | AV:N/AC:H/AT:P/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
rustls-webpki versions prior to 0.103.10
rustls-webpki versions prior to 0.104.0-alpha.5
Description
Faulty CRL (Certificate Revocation List) authority-matching logic occurs when a certificate contains multiple
distributionPoint entries. The system only compares the first distributionPoint against each CRL's IssuingDistributionPoint, ignoring all subsequent entries. This results in correctly provided CRLs not being consulted for revocation checks. If UnknownStatusPolicy::Allow is used, revoked certificates may be inappropriately accepted. Under the default UnknownStatusPolicy::Deny policy, this leads to an incorrect Error::UnknownRevocationStatus. Exploitation requires a compromised trusted issuing authority to present revoked certificates or leverage the faulty checking to continue using revoked credentials.Recommendations
Update rustls-webpki to version 0.103.10 or later.
Update rustls-webpki to version 0.104.0-alpha.5 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rustls-Webpki