{"id":"CVE-2026-93602","title":"rustls-webpki versions before 0.103.10 and 0.104.0-alpha.5 contain faulty CRL authority-matching logic that compares only the first distributionPoint against each CRL's IssuingDistributionPoint, ignoring additional distributionPoints","summary":"rustls-webpki versions before 0.103.10 and 0.104.0-alpha.5 contain faulty CRL authority-matching logic that compares only the first distributionPoint against each CRL's IssuingDistributionPoint, ignoring additional distributionPoints. At…","severity":"medium","cvss":4.4,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N","cwe":["CWE-299"],"vendor":"rustls","product":"webpki","affected":["webpki >= 0.102.0-alpha.0 < 0.103.10","webpki >= 0.104.0-alpha.1 < 0.104.0-alpha.5"],"published":"2026-09-18","updated":"2026-09-18","sourceUpdated":"2026-09-18T18:18:30.757","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-93602","references":[{"url":"https://github.com/rustls/webpki/security/advisories/GHSA-pwjx-qhcg-rvj4","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/rustls-webpki-before-0.103.10-crl-revocation-check-bypass","label":"disclosure@vulncheck.com"},{"url":"https://crates.io/crates/rustls-webpki"},{"url":"https://rustsec.org/advisories/RUSTSEC-2026-0049.html"},{"url":"https://github.com/rustls/webpki"}],"tags":["nvd","cve.org","osv","rust"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-18T17:58:04.007768Z"},"ingestedAt":"2026-09-18T13:41:41.662Z","epss":0.002,"epssPercentile":0.1022,"aliases":["RUSTSEC-2026-0049","GHSA-pwjx-qhcg-rvj4"],"ecosystem":"rust","patched":["rustls-webpki 0.103.10"],"slug":"CVE-2026-93602","body":"## Overview\n\nrustls-webpki versions before 0.103.10 and 0.104.0-alpha.5 contain faulty CRL authority-matching logic that compares only the first distributionPoint against each CRL's IssuingDistributionPoint, ignoring additional distributionPoints. Attackers with a compromised trusted issuing authority can present revoked certificates that pass revocation checks under UnknownStatusPolicy::Allow, or cause incorrect errors under the default deny policy.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-93602)\n\nAffected packages:\n\n- `rustls-webpki >= 0.102.0-alpha.0, < 0.103.10`\n\nPatched in:\n\n- `rustls-webpki 0.103.10`\n\nSource: https://osv.dev/vulnerability/RUSTSEC-2026-0049","depth":"sunlit","depthScore":24,"depthScoreParts":{"impact":24.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}