Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-93600— rustls webpki Name Constraints URI Validation Bypass

Quick assessment

Affected
rustls webpki
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

漏洞描述信息中文翻译: rustls-webpki(rustls/webpki) 0.101.0 至 0.103.11 版本,以及 0.104.0-alpha.6 之前的 0.104.0-alpha 系列版本,会忽略适用于 URI 名称的 X.509 名称约束,导致这些约束被接受而非被执行(即未强制生效)。 由于名称约束是对“已正确签发”的证书施加的限制,该缺陷仅在签名验证成功之后才可被触发,且需要存在一张签发错误的证书才能利用。此外,该库未提供用于断言 URI 名称的 API,且 URI 名称约束在其他方面也未实

CVSS 2.2 · Low

Affected Version Matrix 2

VendorProduct Version RangeStatus
rustls webpki 0.101.0< 0.103.12 affected
0.104.0-alpha.1< 0.104.0-alpha.6 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-93600

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
rustls webpki Name Constraints URI Validation Bypass
Source: CVE Program / CVE List V5
Vulnerability Description
rustls-webpki (rustls/webpki) versions 0.101.0 through 0.103.11 and 0.104.0-alpha releases before 0.104.0-alpha.6 ignore X.509 name constraints that apply to URI names, causing such constraints to be accepted rather than enforced. Because name constraints are restrictions on otherwise properly issued certificates, the flaw is only reachable after successful signature verification and requires a misissued certificate to exploit; the library also provides no API for asserting URI names, and URI name constraints are otherwise unimplemented. Versions 0.103.12 and 0.104.0-alpha.6 reject URI name constraints unconditionally.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
证书验证不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
rustls webpki 0.101.0 ~ 0.103.12 -

II. Public POCs for CVE-2026-93600

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-93600

登录查看更多情报信息。

Other References for CVE-2026-93600 (2)

Same Patch Batch · rustls · 2026-09-18 · 4 CVEs total

CVE-2026-93599 7.5 HIGH rustls-webpki before 0.103.13 Panic via empty BIT STRING
CVE-2026-93602 4.4 MEDIUM rustls-webpki before 0.103.10 CRL Revocation Check Bypass
CVE-2026-93601 2.2 LOW rustls webpki 0.101.0 before 0.103.12 Name Constraint Bypass

IV. Related Vulnerabilities

V. Comments for CVE-2026-93600

No comments yet


Leave a comment