mediumCVSS 4.4Vulnerability

GHSA-pwjx-qhcg-rvj4

If a certificate had more than one `distributionPoint`, then only the first `distributionPoint` would be considered against each CRL's `IssuingDistributionPoint` `distributionPoint`, and then the certificate's subsequent `distributionPoint`s would be ignored. The impact was that correct provided CRLs would not be consulted to check revocation. With `UnknownStatusPolicy::Deny` (the default) this would lead to incorrect but safe `Error::UnknownRevocationStatus`. With `UnknownStatusPolicy::Allow` this would lead to inappropriate acceptance of revoked certificates. This vulnerability is thought to be of limited impact. This is because both the certificate and CRL are signed -- an attacker would need to compromise a trusted issuing authority to trigger this bug. An attacker with such capabilities could likely bypass revocation checking through other more impactful means (such as publishing a valid, empty CRL.) More likely, this bug would be latent in normal use, and an attacker could leverage faulty revocation checking to continue using a revoked credential.

Properties

ghsa_id
GHSA-pwjx-qhcg-rvj4
severity
medium
summary
webpki: CRLs not considered authoritative by Distribution Point due to faulty matching logic
cvss_score
4.4
cve_id
GHSA-pwjx-qhcg-rvj4
cvss_vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N
is_ghsa_only
true
ghsa_published
2026-03-20T21:51:17Z
source_url
https://github.com/advisories/GHSA-pwjx-qhcg-rvj4
ghsa_updated
2026-03-25T19:56:39Z

Related Entities (3)

AFFECTS (1)

[Software]rust/rustls-webpki

HAS_WEAKNESS (1)

[Weakness]Improper Check for Certificate Revocation

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph