---
id: RUSTSEC-2026-0312
aliases:
  - GHSA-39mm-4q6x-3vrx
title: Excluded iPAddress name constraints with an all-zero mask are not applied
summary: Excluded iPAddress name constraints with an all-zero mask are not applied
severity: high
cvss: 7.4
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'
vendor: x509-validator
product: x509-validator
ecosystem: rust
affected:
  - 'x509-validator >= 0.0.0-0, < 0.3.1'
patched:
  - x509-validator 0.3.1
published: '2026-09-24'
updated: '2026-09-28'
sourceUpdated: '2026-09-28T09:45:02.969451461Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/RUSTSEC-2026-0312'
references:
  - url: 'https://crates.io/crates/x509-validator'
  - url: 'https://rustsec.org/advisories/RUSTSEC-2026-0312.html'
  - url: >-
      https://github.com/namecare/x509-validator/commit/da661f8ecee820e05d089a76ecb654ff52a2c987
tags:
  - osv
  - rust
ingestedAt: '2026-09-29T07:20:57.380Z'
---

## Overview

An `excluded_subtrees` iPAddress name constraint with an all-zero mask
(`0.0.0.0/0` or `::/0`) does not restrict iPAddress SANs in certificates issued
beneath it. The mask check treated an all-zero mask as matching nothing, when a
`/0` prefix matches every address of its family, so the exclusion was silently
ignored.

CA/Browser Forum Baseline Requirements §7.1.2.5.2 require exactly these
exclusions on every technically constrained sub-CA that may not issue for IP
addresses. As a result, anyone holding (or having compromised) the key of such
a sub-CA can issue a certificate for an arbitrary IP address, and `Validator`
with `RFC5280Policy` and `ServerIdentityPolicy` accepts it for that address. A
`permitted_subtrees` dNSName entry on the same issuer does not prevent this,
because iPAddress SANs are a different name form.

All users of `Validator` with `RFC5280Policy` are affected when a chain can
contain a name-constrained issuer with an all-zero iPAddress exclusion.

The issue is fixed in x509-validator 0.3.1 (commit
[da661f8](https://github.com/namecare/x509-validator/commit/da661f8ecee820e05d089a76ecb654ff52a2c987)).
Users should upgrade to 0.3.1 or later.

## Affected packages

- `x509-validator >= 0.0.0-0, < 0.3.1`

## Remediation

Upgrade to a patched release:

- `x509-validator 0.3.1`
