lowCVSS 2.2Vulnerability
GHSA-xgp8-3hg3-c2mh
Permitted subtree name constraints for DNS names were accepted for certificates asserting a wildcard name. This was incorrect because, given a name constraint of `accept.example.com`, `*.example.com` could feasibly allow a name of `reject.example.com` which is outside the constraint. This is very similar to [CVE-2025-61727](https://go.dev/issue/76442). Since name constraints are restrictions on otherwise properly-issued certificates, this bug is reachable only after signature verification and requires misissuance to exploit.
Properties
- ghsa_id
- GHSA-xgp8-3hg3-c2mh
- severity
- low
- summary
- webpki: Name constraints were accepted for certificates asserting a wildcard name
- cvss_score
- 2.2
- cve_id
- GHSA-xgp8-3hg3-c2mh
- cvss_vector
- CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N
- is_ghsa_only
- true
- ghsa_published
- 2026-04-16T21:17:12Z
- source_url
- https://github.com/advisories/GHSA-xgp8-3hg3-c2mh
- ghsa_updated
- 2026-04-16T21:17:13Z
Related Entities (4)
VULNERABLE_TO (1)
←[Software]rust/rustls-webpki
AFFECTS (1)
→[Software]rust/rustls-webpki
HAS_WEAKNESS (1)
→[Weakness]Improper Certificate Validation
REPORTED_BY (1)
→[Source]GitHub Advisory Database
Explore deeper with Ninja Signal's threat intelligence graph