rustls 和 webpki 库(版本 up to 0.103.12,以及 0.104.0-alpha.7 之前的 0.104.0-alpha 系列版本)在 中的 函数中存在一个可触发的 panic(程序崩溃)漏洞。 具体来说,输入校验未能拒绝一个命名位(named-bit)BIT STRING,其内容恰好为 (即零个填充位且没有数据字节)。这导致 在空切片上发生下溢:在 debug 模式下表现为减法溢出(subtract-with-overflow),在 release 模式下表现为数组索引越界(index-o
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-93602 | 4.4 MEDIUM | rustls-webpki before 0.103.10 CRL Revocation Check Bypass |
| CVE-2026-93601 | 2.2 LOW | rustls webpki 0.101.0 before 0.103.12 Name Constraint Bypass |
| CVE-2026-93600 | 2.2 LOW | rustls webpki Name Constraints URI Validation Bypass |
No comments yet