Name constraints were accepted for certificates asserting a wildcard name
Fixed in: >= 0.103.12, >= 0.104.0-alpha.6
details
- Finding IDs
- F-RUSTLS-WEBPKI-NAMECONSTRAINTS-WILDCARD-001
- CVE
- CVE-2026-93601
- GHSA
- GHSA-xgp8-3hg3-c2mh
- Status
- patched
- Fixed in
- >= 0.103.12, >= 0.104.0-alpha.6
- Recorded credit
- reporter: @1seal
- Note
- Name constraints were accepted for certificates asserting a wildcard name. CVE-2026-93601: VulnCheck CNA record verified PUBLISHED on 2026-09-23; CVE publication 2026-09-18. Assigned by VulnCheck; the repository GHSA snapshot still has no CVE identifier.
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N
- CVE registry state
- PUBLISHED
- CVE state checked
- Upstream title
- Name constraints were accepted for certificates asserting a wildcard name
- Upstream CWE
- CWE-295
- Upstream publication
- Upstream updated
- Metadata fetched
- Upstream @1seal credit
- @1seal: reporter (accepted)
- CVE mapping note
- Recorded CVE and upstream metadata differ; upstream CVE: not assigned in this snapshot. The recorded mapping has not been changed.
F-RUSTLS-WEBPKI-NAMECONSTRAINTS-WILDCARD-001: Verification failures. Wildcard DNS names bypass constraint checks. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
Mechanism source for F-RUSTLS-WEBPKI-NAMECONSTRAINTS-WILDCARD-001
Security area (1seal assessment): Identity. Wildcard DNS names bypass constraint checks. Reviewed 24 Sep 2026.