CVE-2026-93601

Public on 2026-09-18
Modified on 2026-09-21
Description
rustls-webpki (the Rust webpki fork used by rustls) versions >= 0.101.0 and prior to 0.103.12 and 0.104.0-alpha.6 incorrectly accepted permitted-subtree DNS name constraints for certificates asserting a wildcard name. For example, a name constraint of accept.example.com was treated as satisfied by a certificate for *.example.com, which could feasibly assert reject.example.com — a name outside the permitted subtree. Because name constraints are restrictions applied to otherwise properly issued certificates, the issue is only reachable after signature verification succeeds and requires a misissued wildcard certificate to exploit.
Severity
Low severity
Low
See what this means
CVSS v3 Base Score
2.2
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2 - Core amazon-efs-utils Pending Fix
Amazon Linux 2023 amazon-efs-utils Pending Fix
Amazon Linux 2027 Preview amazon-efs-utils Pending Fix
Amazon Linux 2027 Preview aws-nitro-enclaves-cli Pending Fix
Amazon Linux 2023 aws-workload-credentials-provider Pending Fix
Amazon Linux 2027 Preview network-flow-monitor-agent Not Affected

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 2.2 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N