在 rustls-webpki 0.103.10 之前及 0.104.0-alpha.5 之前版本中,存在有缺陷的 CRL 颁发机构匹配逻辑:该逻辑仅将 CRL 的 IssuingDistributionPoint 与第一个 distributionPoint 进行比较,而忽略了额外的 distributionPoints。若攻击者拥有一个被攻陷的可信颁发机构,他们可以出示已被吊销但通过吊销检查(在 策略下)的证书,或在默认的拒绝策略下引发错误的错误信息。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-93599 | 7.5 HIGH | rustls-webpki before 0.103.13 Panic via empty BIT STRING |
| CVE-2026-93601 | 2.2 LOW | rustls webpki 0.101.0 before 0.103.12 Name Constraint Bypass |
| CVE-2026-93600 | 2.2 LOW | rustls webpki Name Constraints URI Validation Bypass |
No comments yet