漏洞描述信息中文翻译: rustls-webpki(rustls/webpki) 0.101.0 至 0.103.11 版本,以及 0.104.0-alpha.6 之前的 0.104.0-alpha 系列版本,会忽略适用于 URI 名称的 X.509 名称约束,导致这些约束被接受而非被执行(即未强制生效)。 由于名称约束是对“已正确签发”的证书施加的限制,该缺陷仅在签名验证成功之后才可被触发,且需要存在一张签发错误的证书才能利用。此外,该库未提供用于断言 URI 名称的 API,且 URI 名称约束在其他方面也未实
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-93599 | 7.5 HIGH | rustls-webpki before 0.103.13 Panic via empty BIT STRING |
| CVE-2026-93602 | 4.4 MEDIUM | rustls-webpki before 0.103.10 CRL Revocation Check Bypass |
| CVE-2026-93601 | 2.2 LOW | rustls webpki 0.101.0 before 0.103.12 Name Constraint Bypass |
No comments yet