CVE-2026-93600
Public on 2026-09-18
Modified on 2026-09-21
Description
rustls-webpki (rustls/webpki) versions 0.101.0 through 0.103.11 and 0.104.0-alpha releases before 0.104.0-alpha.6 ignore X.509 name constraints that apply to URI names, causing such constraints to be accepted rather than enforced. Because name constraints are restrictions on otherwise properly issued certificates, the flaw is only reachable after successful signature verification and requires a misissued certificate to exploit; the library also provides no API for asserting URI names, and URI name constraints are otherwise unimplemented. Versions 0.103.12 and 0.104.0-alpha.6 reject URI name constraints unconditionally.
Severity
See what this means
CVSS v3 Base Score
See breakdown
Affected Packages
| Platform | Package | Release Date | Advisory | Status |
|---|---|---|---|---|
| Amazon Linux 2 - Core | amazon-efs-utils | Pending Fix | ||
| Amazon Linux 2023 | amazon-efs-utils | Pending Fix | ||
| Amazon Linux 2027 Preview | amazon-efs-utils | Pending Fix | ||
| Amazon Linux 2027 Preview | aws-nitro-enclaves-cli | Pending Fix | ||
| Amazon Linux 2023 | aws-workload-credentials-provider | Pending Fix | ||
| Amazon Linux 2027 Preview | network-flow-monitor-agent | Not Affected |
CVSS Scores
| Score Type | Score | Vector | |
|---|---|---|---|
| Amazon Linux | CVSSv3 | 3.7 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N |