CRLs not considered authoritative by Distribution Point due to faulty matching logic
Fixed in: 0.104.0-alpha.5, 0.103.10
patched
details
Finding IDs
F-RUSTLS-WEBPKI-001
CVE
CVE-2026-93602
GHSA
GHSA-pwjx-qhcg-rvj4
Status
patched
Fixed in
0.104.0-alpha.5, 0.103.10
Note
CVE-2026-93602: VulnCheck CNA record verified PUBLISHED on 2026-09-23; CVE publication 2026-09-18. Assigned by VulnCheck; the repository GHSA snapshot still has no CVE identifier.
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N
CVE registry state
PUBLISHED
CVE state checked
Upstream title
CRLs not considered authoritative by Distribution Point due to faulty matching logic
Upstream CWE
CWE-299
Upstream publication
Upstream updated
Metadata fetched
Upstream @1seal credit
@1seal: reporter (accepted)
CVE mapping note
Recorded CVE and upstream metadata differ; upstream CVE: not assigned in this snapshot. The recorded mapping has not been changed.
F-RUSTLS-WEBPKI-001: Verification failures. CRL authority matching is incomplete. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
This identifier groups recorded evidence; it is not an additional CVE, independent-vulnerability count or guarantee of vendor confirmation. Fixed code, released versions, attribution and independent discovery are distinct claims. Absent metadata means not recorded, not disproved. Counting rules.