Impact
A flaw in the certificate revocation list (CRL) authority matching logic in rustls-webpki, classified as CWE-295 and CWE-299 weaknesses, allows an attacker with access to a compromised trusted issuing authority to present revoked certificates that pass revocation checks when the policy allows unknown status, or to trigger incorrect errors under the default deny policy. This bypass means that certificates that should be considered untrustworthy can be accepted, potentially enabling man‑in‑the‑middle or other unauthorized TLS connections.
Affected Systems
rustls:webpki versions before 0.103.10 and before 0.104.0‑alpha.5 are affected. These versions are used by Rust projects that rely on rustls for TLS communication.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity. The EPSS score is 0.002, indicating a very low exploit probability. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker to have authority over the issuing entity or to influence the CRL distribution points. Once the attacker can supply a CRL that bypasses the logic, revoked certificates will be accepted, allowing the attacker to use previously revoked credentials to establish secure connections.
OpenCVE Enrichment