CVE-2026-93601: Improper Certificate Validation in rustls webpki
rustls-webpki (the Rust webpki fork used by rustls) versions >= 0.101.0 and prior to 0.103.12 and 0.104.0-alpha.6 incorrectly accepted permitted-subtree DNS name constraints for certificates asserting a wildcard name. For example, a name constraint of accept.example.com was treated as satisfied by a certificate for *.example.com, which could feasibly assert reject.example.com — a name outside the permitted subtree. Because name constraints are restrictions applied to otherwise properly issued certificates, the issue is only reachable after signature verification succeeds and requires a misissued wildcard certificate to exploit.
AI Analysis
Technical Summary
The rustls-webpki library versions >=0.101.0 and prior to 0.103.12 and 0.104.0-alpha.6 incorrectly accept permitted-subtree DNS name constraints for certificates asserting wildcard names. Specifically, a name constraint such as accept.example.com was erroneously treated as satisfied by a certificate for *.example.com, which could assert reject.example.com, a name outside the permitted subtree. This flaw arises because name constraints are meant to restrict otherwise valid certificates, and the issue is only exploitable after the certificate signature verification succeeds, requiring a misissued wildcard certificate.
Potential Impact
This vulnerability could allow a certificate with a wildcard name to assert DNS names outside the permitted subtree defined by name constraints, potentially enabling unauthorized use of domain names. However, exploitation requires a misissued wildcard certificate and occurs only after successful signature verification. The CVSS score of 2.1 indicates low severity, reflecting limited impact and high attack complexity.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Users should monitor rustls-webpki releases for updates addressing this issue and apply official fixes when available. Until then, be aware of the risk posed by misissued wildcard certificates in affected versions.
CVE-2026-93601: Improper Certificate Validation in rustls webpki
Description
rustls-webpki (the Rust webpki fork used by rustls) versions >= 0.101.0 and prior to 0.103.12 and 0.104.0-alpha.6 incorrectly accepted permitted-subtree DNS name constraints for certificates asserting a wildcard name. For example, a name constraint of accept.example.com was treated as satisfied by a certificate for *.example.com, which could feasibly assert reject.example.com — a name outside the permitted subtree. Because name constraints are restrictions applied to otherwise properly issued certificates, the issue is only reachable after signature verification succeeds and requires a misissued wildcard certificate to exploit.
CVSS v4.0
Score 2.1low
Affected software
rustls
webpki
pkg:cargo/rustls/webpkiRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The rustls-webpki library versions >=0.101.0 and prior to 0.103.12 and 0.104.0-alpha.6 incorrectly accept permitted-subtree DNS name constraints for certificates asserting wildcard names. Specifically, a name constraint such as accept.example.com was erroneously treated as satisfied by a certificate for *.example.com, which could assert reject.example.com, a name outside the permitted subtree. This flaw arises because name constraints are meant to restrict otherwise valid certificates, and the issue is only exploitable after the certificate signature verification succeeds, requiring a misissued wildcard certificate.
Potential Impact
This vulnerability could allow a certificate with a wildcard name to assert DNS names outside the permitted subtree defined by name constraints, potentially enabling unauthorized use of domain names. However, exploitation requires a misissued wildcard certificate and occurs only after successful signature verification. The CVSS score of 2.1 indicates low severity, reflecting limited impact and high attack complexity.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Users should monitor rustls-webpki releases for updates addressing this issue and apply official fixes when available. Until then, be aware of the risk posed by misissued wildcard certificates in affected versions.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-09-18T11:00:32.756Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6aad3d5d55bf5e2cf5100794
Added to database: 09/18/2026, 13:32:13 UTC
Last enriched: 09/18/2026, 13:47:30 UTC
Last updated: 09/18/2026, 18:25:05 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.