Junglewise Threat Intelligence

CVE-2026-93602: rustls-webpki CRL distribution point matching bypass

CVE-2026-93602 · Severity: medium · CVSS 4.4 · Published 2026-09-18

Technologies: rustls-webpki (crates.io), Rustls Webpki. Vendors: crates.io, Rustls.

Executive brief

rustls-webpki is a certificate validation library used in Rust applications to verify that SSL/TLS certificates are legitimate and not revoked. The library contains a flaw in its revocation checking logic that causes it to ignore multiple revocation distribution points in a certificate, checking only the first one. An attacker who has compromised a trusted certificate authority could exploit this to use revoked certificates that should be blocked, potentially enabling credential theft or man-in-the-middle attacks.

Technical details

rustls-webpki's CRL (Certificate Revocation List) validation logic fails to properly match multiple distribution points in X.509 certificates. When a certificate specifies multiple distributionPoint values, only the first is compared against each CRL's IssuingDistributionPoint; subsequent distribution points are ignored. This is a CWE-299 improper certificate revocation check. The vulnerability requires an attacker to have compromised a trusted issuing certificate authority to craft a malicious certificate and corresponding CRL. Under the permissive UnknownStatusPolicy::Allow policy, revoked certificates will be incorrectly accepted; under the default deny policy, legitimate certificates may be rejected with spurious revocation status errors. Patches are available in rustls-webpki 0.103.10 and 0.104.0-alpha.5 or later.

Affected products

  • rustls webpki >=0.101.0, <0.103.10 or >=0.104.0-alpha.1, <0.104.0-alpha.5

Timeline

  • 2026-03-20: disclosed
  • 2026-09-18: advisory
  • 2026-03-20: patched: patches released in 0.103.10 and 0.104.0-alpha.5

References

Related threats