lowCVSS 2.2Vulnerability

GHSA-965h-392x-2mh5

Name constraints for URI names were ignored and therefore accepted. Note this library does not provide an API for asserting URI names, and URI name constraints are otherwise not implemented. URI name constraints are now rejected unconditionally. Since name constraints are restrictions on otherwise properly-issued certificates, this bug is reachable only after signature verification and requires misissuance to exploit.

Properties

ghsa_id
GHSA-965h-392x-2mh5
severity
low
summary
webpki: Name constraints for URI names were incorrectly accepted
cvss_score
2.2
cve_id
GHSA-965h-392x-2mh5
cvss_vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N
is_ghsa_only
true
ghsa_published
2026-04-16T21:16:22Z
source_url
https://github.com/advisories/GHSA-965h-392x-2mh5
ghsa_updated
2026-04-16T21:16:23Z

Related Entities (4)

VULNERABLE_TO (1)

[Software]rust/rustls-webpki

AFFECTS (1)

[Software]rust/rustls-webpki

HAS_WEAKNESS (1)

[Weakness]Improper Certificate Validation

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-965h-392x-2mh5 (CVSS 2.2) — Ninja Signal Threat Intelligence | Ninja Signal