GHSA-pwjx-qhcg-rvj4
If a certificate had more than one `distributionPoint`, then only the first `distributionPoint` would be considered against each CRL's `IssuingDistributionPoint` `distributionPoint`, and then the certificate's subsequent `distributionPoint`s would be ignored. The impact was that correct provided CRLs would not be consulted to check revocation. With `UnknownStatusPolicy::Deny` (the default) this would lead to incorrect but safe `Error::UnknownRevocationStatus`. With `UnknownStatusPolicy::Allow` this would lead to inappropriate acceptance of revoked certificates. This vulnerability is thought to be of limited impact. This is because both the certificate and CRL are signed -- an attacker would need to compromise a trusted issuing authority to trigger this bug. An attacker with such capabilities could likely bypass revocation checking through other more impactful means (such as publishing a valid, empty CRL.) More likely, this bug would be latent in normal use, and an attacker could leverage faulty revocation checking to continue using a revoked credential.
Properties
- ghsa_id
- GHSA-pwjx-qhcg-rvj4
- severity
- medium
- summary
- webpki: CRLs not considered authoritative by Distribution Point due to faulty matching logic
- cvss_score
- 4.4
- cve_id
- GHSA-pwjx-qhcg-rvj4
- cvss_vector
- CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N
- is_ghsa_only
- true
- ghsa_published
- 2026-03-20T21:51:17Z
- source_url
- https://github.com/advisories/GHSA-pwjx-qhcg-rvj4
- ghsa_updated
- 2026-03-25T19:56:39Z
Related Entities (3)
AFFECTS (1)
HAS_WEAKNESS (1)
REPORTED_BY (1)
Explore deeper with Ninja Signal's threat intelligence graph