rustls-webpki vulnerabilities
CVEs whose affected-version data names the rustls-webpki package (rust). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
4 CVEsRSS
RUSTSEC-2026-0104NoneReachable panic in certificate revocation list parsing
Reachable panic in certificate revocation list parsing
▾ Sunlitrustls-webpki · rustls-webpkivia OSV
RUSTSEC-2026-0099NoneName constraints were accepted for certificates asserting a wildcard name
Name constraints were accepted for certificates asserting a wildcard name
▾ Sunlitrustls-webpki · rustls-webpkivia OSV
RUSTSEC-2026-0098NoneName constraints for URI names were incorrectly accepted
Name constraints for URI names were incorrectly accepted
▾ Sunlitrustls-webpki · rustls-webpkivia OSV
RUSTSEC-2026-0049NoneCRLs not considered authoritative by Distribution Point due to faulty matching logic
CRLs not considered authoritative by Distribution Point due to faulty matching logic
▾ Sunlitrustls-webpki · rustls-webpkivia OSV