Skip to main content

CVE-2026-93599: Integer Underflow (Wrap or Wraparound) in rustls webpki

0
High
VulnerabilityCVE-2026-93599cvecve-2026-93599
Published: 09/18/2026 (09/18/2026, 13:20:10 UTC)
Source: CVE Database V5
Vendor/Project: rustls
Product: webpki

Description

rustls-webpki through 0.103.12 (and 0.104.0-alpha releases before 0.104.0-alpha.7) contains a reachable panic in bit_string_flags() in src/der.rs. The input guard fails to reject a named-bit BIT STRING whose content is exactly [0x00] (zero padding bits and no data bytes), so raw_bits.len() - 1 underflows on the empty slice and the subsequent index operation panics (subtract-with-overflow in debug, index-out-of-bounds in release). The condition is reachable through the public API BorrowedCertRevocationList::from_der() when a CRL contains an issuingDistributionPoint extension with such an onlySomeReasons value. Exploitation requires an application that explicitly opts in to CRL revocation checking by passing RevocationOptions to verify_for_usage() and that parses CRL bytes obtained from a source the attacker can influence; the default rustls configuration, which does not use RevocationOptions, is unaffected. A crafted CRL causes a denial of service via the panic. Fixed in 0.103.13 and 0.104.0-alpha.7.

CVSS v4.0

Score 8.7high

Attack Vector
Network
Attack Complexity
Low
Attack Requirements
None
Privileges Required
None
User Interaction
None
Vuln. Confidentiality
None
Vuln. Integrity
None
Vuln. Availability
High
Subsq. Confidentiality
None
Subsq. Integrity
None
Subsq. Availability
None
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Affected software

rustls

webpki

Affected versions
>=0 <0.103.13>=0.104.0-alpha.1 <0.104.0-alpha.7
crates.iomore threats →ai
rustls/webpki
pkg:cargo/rustls/webpki
Affected versions
<0.103.13>=0.104.0-alpha.1 <0.104.0-alpha.7

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/18/2026, 13:46:59 UTC

Technical Analysis

The vulnerability exists in rustls-webpki through 0.103.12 and 0.104.0-alpha releases before 0.104.0-alpha.7 in the bit_string_flags() function in src/der.rs. A named-bit BIT STRING with content [0x00] is not rejected, causing raw_bits.len() - 1 to underflow on an empty slice, leading to a panic (index out-of-bounds). This can be triggered via the public API BorrowedCertRevocationList::from_der() when parsing a CRL with an issuingDistributionPoint extension containing such a value. Exploitation requires the application to explicitly enable CRL revocation checking with RevocationOptions and to parse attacker-controlled CRL bytes. The default rustls configuration is unaffected. The flaw results in denial of service via panic. Fixed in 0.103.13 and 0.104.0-alpha.7.

Potential Impact

An attacker who can supply a crafted CRL to an application that explicitly enables CRL revocation checking can cause the application to panic and crash, resulting in denial of service. There is no indication of code execution or information disclosure. The default rustls configuration without RevocationOptions is not vulnerable.

Mitigation Recommendations

Upgrade rustls-webpki to version 0.103.13 or later, or to 0.104.0-alpha.7 or later for alpha releases. Applications that do not enable CRL revocation checking with RevocationOptions are not affected and require no action.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
VulnCheck
Date Reserved
2026-09-18T11:00:32.755Z
Cvss Version
4.0
State
PUBLISHED

Threat ID: 6aad3d5b55bf5e2cf51004f5

Added to database: 09/18/2026, 13:32:11 UTC

Last enriched: 09/18/2026, 13:46:59 UTC

Last updated: 09/18/2026, 16:02:02 UTC

Views: 7

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses