Impact
The vulnerability is caused by rustls/webpki misinterpreting name‑constraint rules when validating certificates that contain a wildcard subject. A permitted‑subtree constraint such as accept.example.com is evaluated as satisfied by a certificate for *.example.com, even though a certificate for reject.example.com, which is outside the intended subtree, can also be represented by the same wildcard. This flaw is only reachable after the certificate’s signature has been verified, and thus requires a misissued wildcard certificate that matches the domain. The flaw aligns with CWE-1289 and CWE-295.
Affected Systems
The affected component is the rustls/webpki library used by the Rust ecosystem for TLS certificate validation. Versions 0.101.0 through 0.103.11 inclusive, as well as 0.104.0‑alpha.6, are vulnerable. Any Rust application that links to one of these library versions, including servers and clients that rely on rustls for secure connections, is impacted until the library is upgraded to 0.103.12 or later.
Risk and Exploitability
The CVSS score of 2.1 indicates low severity, and the EPSS score of < 1% indicates a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires a misissued wildcard certificate that passes initial signature checks and a system that enforces name‑constraint validation. Because the flaw only becomes active after the certificate passes normal integrity checks, the attack surface is limited to scenarios where strict name‑constraint enforcement is used; nevertheless, a successful bypass could allow an attacker to impersonate a domain trusted by the application. The weakness is formally identified as CWE-1289 and CWE-295.
OpenCVE Enrichment