{"id":"RUSTSEC-2026-0312","aliases":["GHSA-39mm-4q6x-3vrx"],"title":"Excluded iPAddress name constraints with an all-zero mask are not applied","summary":"Excluded iPAddress name constraints with an all-zero mask are not applied","severity":"high","cvss":7.4,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","vendor":"x509-validator","product":"x509-validator","ecosystem":"rust","affected":["x509-validator >= 0.0.0-0, < 0.3.1"],"patched":["x509-validator 0.3.1"],"published":"2026-09-24","updated":"2026-09-28","sourceUpdated":"2026-09-28T09:45:02.969451461Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/RUSTSEC-2026-0312","references":[{"url":"https://crates.io/crates/x509-validator"},{"url":"https://rustsec.org/advisories/RUSTSEC-2026-0312.html"},{"url":"https://github.com/namecare/x509-validator/commit/da661f8ecee820e05d089a76ecb654ff52a2c987"}],"tags":["osv","rust"],"ingestedAt":"2026-09-29T07:20:57.380Z","slug":"RUSTSEC-2026-0312","body":"## Overview\n\nAn `excluded_subtrees` iPAddress name constraint with an all-zero mask\n(`0.0.0.0/0` or `::/0`) does not restrict iPAddress SANs in certificates issued\nbeneath it. The mask check treated an all-zero mask as matching nothing, when a\n`/0` prefix matches every address of its family, so the exclusion was silently\nignored.\n\nCA/Browser Forum Baseline Requirements §7.1.2.5.2 require exactly these\nexclusions on every technically constrained sub-CA that may not issue for IP\naddresses. As a result, anyone holding (or having compromised) the key of such\na sub-CA can issue a certificate for an arbitrary IP address, and `Validator`\nwith `RFC5280Policy` and `ServerIdentityPolicy` accepts it for that address. A\n`permitted_subtrees` dNSName entry on the same issuer does not prevent this,\nbecause iPAddress SANs are a different name form.\n\nAll users of `Validator` with `RFC5280Policy` are affected when a chain can\ncontain a name-constrained issuer with an all-zero iPAddress exclusion.\n\nThe issue is fixed in x509-validator 0.3.1 (commit\n[da661f8](https://github.com/namecare/x509-validator/commit/da661f8ecee820e05d089a76ecb654ff52a2c987)).\nUsers should upgrade to 0.3.1 or later.\n\n## Affected packages\n\n- `x509-validator >= 0.0.0-0, < 0.3.1`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `x509-validator 0.3.1`","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":40.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}