Description
rustls-webpki versions before 0.103.10 and 0.104.0-alpha.5 contain faulty CRL authority-matching logic that compares only the first distributionPoint against each CRL's IssuingDistributionPoint, ignoring additional distributionPoints. Attackers with a compromised trusted issuing authority can present revoked certificates that pass revocation checks under UnknownStatusPolicy::Allow, or cause incorrect errors under the default deny policy.
Published: 2026-09-18
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Certificate Revocation Bypass
Action: Apply Patch
AI Analysis

Impact

A flaw in the certificate revocation list (CRL) authority matching logic in rustls-webpki, classified as CWE-295 and CWE-299 weaknesses, allows an attacker with access to a compromised trusted issuing authority to present revoked certificates that pass revocation checks when the policy allows unknown status, or to trigger incorrect errors under the default deny policy. This bypass means that certificates that should be considered untrustworthy can be accepted, potentially enabling man‑in‑the‑middle or other unauthorized TLS connections.

Affected Systems

rustls:webpki versions before 0.103.10 and before 0.104.0‑alpha.5 are affected. These versions are used by Rust projects that rely on rustls for TLS communication.

Risk and Exploitability

The CVSS score of 5.9 indicates moderate severity. The EPSS score is 0.002, indicating a very low exploit probability. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker to have authority over the issuing entity or to influence the CRL distribution points. Once the attacker can supply a CRL that bypasses the logic, revoked certificates will be accepted, allowing the attacker to use previously revoked credentials to establish secure connections.

Generated by OpenCVE AI on September 23, 2026 at 01:40 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade rustls-webpki to version 0.103.10 or later, or to 0.104.0‑alpha.5 or newer.
  • If a patch cannot be applied immediately, configure the application to use the default deny policy for unknown CRL statuses, which limits the impact of a bypass under Allow.
  • Verify that no compromised trusted issuing authorities are present and consider disabling CRL checks if the application can safely rely on other revocation mechanisms such as OCSP.

Generated by OpenCVE AI on September 23, 2026 at 01:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-295
References
Metrics threat_severity

None

threat_severity

Moderate


Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Rustls
Rustls webpki
Vendors & Products Rustls
Rustls webpki

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description rustls-webpki versions before 0.103.10 and 0.104.0-alpha.5 contain faulty CRL authority-matching logic that compares only the first distributionPoint against each CRL's IssuingDistributionPoint, ignoring additional distributionPoints. Attackers with a compromised trusted issuing authority can present revoked certificates that pass revocation checks under UnknownStatusPolicy::Allow, or cause incorrect errors under the default deny policy.
Title rustls-webpki before 0.103.10 CRL Revocation Check Bypass
Weaknesses CWE-299
References
Metrics cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N'}

cvssV4_0

{'score': 5.9, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-18T17:58:12.511Z

Reserved: 2026-09-18T11:00:32.756Z

Link: CVE-2026-93602

cve-icon Vulnrichment

Updated: 2026-09-18T17:58:08.871Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T14:19:11.850

Modified: 2026-09-22T20:25:55.870

Link: CVE-2026-93602

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-18T13:20:12Z

Links: CVE-2026-93602 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T01:45:19Z

Weaknesses
  • CWE-295

    Improper Certificate Validation

  • CWE-299

    Improper Check for Certificate Revocation