Impact
The flaw in rustls's webpki library causes the ignoring of X.509 name constraints that apply to URI fields. Because name constraints are restrictive controls that limit the set of valid certificates, this omission allows a certificate chain that would normally be rejected to be accepted after normal signature verification. The impact is limited to the acceptance of certificates that violate established constraints, potentially enabling a malicious actor to present a forged server certificate. This is a low‑severity issue (CVSS 2.1) as it requires the attacker to supply a misissued certificate and does not provide direct code execution or privilege escalation capabilities.
Affected Systems
Affected releases are rustls/webpki versions 0.101.0 through 0.103.11 and early 0.104.0‑alpha releases before 0.104.0‑alpha.6. All users of these library versions that rely on webpki for TLS certificate validation are impacted. Version 0.103.12 and 0.104.0‑alpha.6 have the bug fixed and should be used instead.
Risk and Exploitability
The CVSS score of 2.1 indicates a low severity, and the EPSS score is < 1%. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a misissued certificate that passes signature verification and contains URI fields that are ignored by the library, suggesting the likely attack vector involves a malicious certificate presented during TLS handshakes. Because the library itself does not provide an API for asserting URI names, the flaw is strictly a validation bypass rather than a direct exploitation channel.
OpenCVE Enrichment