lowCVSS 2.2Vulnerability

GHSA-xgp8-3hg3-c2mh

Permitted subtree name constraints for DNS names were accepted for certificates asserting a wildcard name. This was incorrect because, given a name constraint of `accept.example.com`, `*.example.com` could feasibly allow a name of `reject.example.com` which is outside the constraint. This is very similar to [CVE-2025-61727](https://go.dev/issue/76442). Since name constraints are restrictions on otherwise properly-issued certificates, this bug is reachable only after signature verification and requires misissuance to exploit.

Properties

ghsa_id
GHSA-xgp8-3hg3-c2mh
severity
low
summary
webpki: Name constraints were accepted for certificates asserting a wildcard name
cvss_score
2.2
cve_id
GHSA-xgp8-3hg3-c2mh
cvss_vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N
is_ghsa_only
true
ghsa_published
2026-04-16T21:17:12Z
source_url
https://github.com/advisories/GHSA-xgp8-3hg3-c2mh
ghsa_updated
2026-04-16T21:17:13Z

Related Entities (4)

VULNERABLE_TO (1)

[Software]rust/rustls-webpki

AFFECTS (1)

[Software]rust/rustls-webpki

HAS_WEAKNESS (1)

[Weakness]Improper Certificate Validation

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-xgp8-3hg3-c2mh (CVSS 2.2) — Ninja Signal Threat Intelligence | Ninja Signal