rustls-webpki
crates.io4 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting rustls-webpkipage 1 of 1
- CVE-2026-93599HIGHCVSS 7.5EG 7.5✓ Fixed in 0.103.132026-09-18
rustls-webpki through 0.103.12 (and 0.104.0-alpha releases before 0.104.0-alpha.7) contains a reachable panic in bit_string_flags() in src/der.rs. The input guard fails to reject a named-bit BIT STRING whose content is exactly [0x00] (zero…
- CVE-2026-93600LOWCVSS 2.2EG 2.2✓ Fixed in 0.103.122026-09-18
rustls-webpki (rustls/webpki) versions 0.101.0 through 0.103.11 and 0.104.0-alpha releases before 0.104.0-alpha.6 ignore X.509 name constraints that apply to URI names, causing such constraints to be accepted rather than enforced. Because …
- CVE-2026-93601LOWCVSS 2.2EG 2.2✓ Fixed in 0.103.122026-09-18
rustls-webpki (the Rust webpki fork used by rustls) versions >= 0.101.0 and prior to 0.103.12 and 0.104.0-alpha.6 incorrectly accepted permitted-subtree DNS name constraints for certificates asserting a wildcard name. For example, a name c…
- CVE-2026-93602MEDIUMCVSS 4.4EG 4.4✓ Fixed in 0.103.102026-09-18
rustls-webpki versions before 0.103.10 and 0.104.0-alpha.5 contain faulty CRL authority-matching logic that compares only the first distributionPoint against each CRL's IssuingDistributionPoint, ignoring additional distributionPoints. Atta…
Check whether rustls-webpki is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for rustls-webpki CVEs against the assets you own.
Start Free Scan →