CVE-2026-93602
Public on 2026-09-18
Modified on 2026-09-21
Description
rustls-webpki versions before 0.103.10 and 0.104.0-alpha.5 contain faulty CRL authority-matching logic that compares only the first distributionPoint against each CRL's IssuingDistributionPoint, ignoring additional distributionPoints. Attackers with a compromised trusted issuing authority can present revoked certificates that pass revocation checks under UnknownStatusPolicy::Allow, or cause incorrect errors under the default deny policy.
Severity
See what this means
CVSS v3 Base Score
See breakdown
Affected Packages
| Platform | Package | Release Date | Advisory | Status |
|---|---|---|---|---|
| Amazon Linux 2 - Core | amazon-efs-utils | Not Affected | ||
| Amazon Linux 2023 | amazon-efs-utils | Not Affected | ||
| Amazon Linux 2027 Preview | amazon-efs-utils | Not Affected | ||
| Amazon Linux 2027 Preview | aws-nitro-enclaves-cli | Not Affected | ||
| Amazon Linux 2023 | aws-workload-credentials-provider | Not Affected | ||
| Amazon Linux 2027 Preview | network-flow-monitor-agent | Not Affected |
CVSS Scores
| Score Type | Score | Vector | |
|---|---|---|---|
| Amazon Linux | CVSSv3 | 4.8 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N |