Description
rustls-webpki through 0.103.12 (and 0.104.0-alpha releases before 0.104.0-alpha.7) contains a reachable panic in bit_string_flags() in src/der.rs. The input guard fails to reject a named-bit BIT STRING whose content is exactly [0x00] (zero padding bits and no data bytes), so raw_bits.len() - 1 underflows on the empty slice and the subsequent index operation panics (subtract-with-overflow in debug, index-out-of-bounds in release). The condition is reachable through the public API BorrowedCertRevocationList::from_der() when a CRL contains an issuingDistributionPoint extension with such an onlySomeReasons value. Exploitation requires an application that explicitly opts in to CRL revocation checking by passing RevocationOptions to verify_for_usage() and that parses CRL bytes obtained from a source the attacker can influence; the default rustls configuration, which does not use RevocationOptions, is unaffected. A crafted CRL causes a denial of service via the panic. Fixed in 0.103.13 and 0.104.0-alpha.7.
Published: 2026-09-18
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

The vulnerability exists in rustls-webpki where parsing a CRL containing an empty BIT STRING fails to reject a named-bit BIT STRING with content [0x00], causing an underflow in bit_string_flags() that results in a panic. This crash is triggered through the BorrowedCertRevocationList::from_der() API and leads to denial of service for applications that enable CRL revocation checking. A properly crafted certificate revocation list can bring a rustls-enabled server to a halt.

Affected Systems

The affected library is rustls-webpki. Vulnerable versions include 0.103.12 and any 0.104.0‑alpha release before 0.104.0‑alpha.7. The patch is available in 0.103.13 and 0.104.0‑alpha.7 onward. Systems that use rustls at these versions and enable revocation options are at risk.

Risk and Exploitability

The CVSS score of 8.7 indicates a high severity vulnerability. The EPSS score is reported as < 1%, and the absence of a KEV listing suggests no widespread exploitation has yet been observed. The exploit requires an application that explicitly opts in to CRL verification and is fed a CRL from an attacker-controlled source, which is usually supplied over the network. Thus, a malicious actor could deliver a crafted CRL to any rustls-enabled service that uses CRL revocation checking, causing the service to panic and crash. The lack of default revocation checking in rustls mitigates the risk for most deployments; however, services that have enabled RevocationOptions are susceptible to this denial of service.

Generated by OpenCVE AI on September 23, 2026 at 01:41 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update rustls-webpki to 0.103.13 or later, or to 0.104.0‑alpha.7 or newer.
  • If an upgrade cannot be performed immediately, disable CRL revocation checking by omitting RevocationOptions in verify_for_usage().
  • As a temporary measure, validate incoming CRL data to reject BIT STRING values consisting solely of zero padding before passing to BorrowedCertRevocationList::from_der()

Generated by OpenCVE AI on September 23, 2026 at 01:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
References
Metrics threat_severity

None

threat_severity

Important


Sun, 20 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Rustls
Rustls webpki
Vendors & Products Rustls
Rustls webpki

Fri, 18 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description rustls-webpki through 0.103.12 (and 0.104.0-alpha releases before 0.104.0-alpha.7) contains a reachable panic in bit_string_flags() in src/der.rs. The input guard fails to reject a named-bit BIT STRING whose content is exactly [0x00] (zero padding bits and no data bytes), so raw_bits.len() - 1 underflows on the empty slice and the subsequent index operation panics (subtract-with-overflow in debug, index-out-of-bounds in release). The condition is reachable through the public API BorrowedCertRevocationList::from_der() when a CRL contains an issuingDistributionPoint extension with such an onlySomeReasons value. Exploitation requires an application that explicitly opts in to CRL revocation checking by passing RevocationOptions to verify_for_usage() and that parses CRL bytes obtained from a source the attacker can influence; the default rustls configuration, which does not use RevocationOptions, is unaffected. A crafted CRL causes a denial of service via the panic. Fixed in 0.103.13 and 0.104.0-alpha.7.
Title rustls-webpki before 0.103.13 Panic via empty BIT STRING
Weaknesses CWE-191
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-18T14:15:25.188Z

Reserved: 2026-09-18T11:00:32.755Z

Link: CVE-2026-93599

cve-icon Vulnrichment

Updated: 2026-09-18T14:09:18.314Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T14:19:11.410

Modified: 2026-09-22T20:25:55.870

Link: CVE-2026-93599

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-18T13:20:10Z

Links: CVE-2026-93599 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T01:45:19Z

Weaknesses
  • CWE-125

    Out-of-bounds Read

  • CWE-191

    Integer Underflow (Wrap or Wraparound)