Junglewise Threat Intelligence

CVE-2026-93601: rustls-webpki name constraint bypass for wildcard certificates

CVE-2026-93601 · Severity: low · CVSS 3.1 · Published 2026-09-18

Technologies: rustls-webpki (crates.io), Rustls Webpki. Vendors: crates.io, Rustls.

Executive brief

rustls-webpki is a certificate validation library used by the Rust TLS implementation. A flaw in name constraint validation allows wildcard certificates to bypass DNS name restrictions that were otherwise properly issued. An attacker with a misissued wildcard certificate could assert domain names outside their permitted scope, potentially enabling domain impersonation attacks.

Technical details

The vulnerability is an improper certificate validation (CWE-295) in name constraint handling. When a certificate asserts a wildcard DNS name (e.g., *.example.com), the library incorrectly accepted permitted-subtree name constraints as satisfied. For example, a constraint of accept.example.com would be satisfied by *.example.com, which could feasibly cover reject.example.com—a name outside the permitted subtree. This occurs only after signature verification succeeds and requires a misissued wildcard certificate to reach. Patches are available in versions 0.103.12 and 0.104.0-alpha.6 or later.

Affected products

  • rustls webpki >= 0.101.0, < 0.103.12; >= 0.104.0-alpha.1, < 0.104.0-alpha.6

Timeline

  • 2026-04-15: disclosed: GitHub security advisory published
  • 2026-09-18: advisory: CVE-2026-93601 published

References

Related threats