VulnSea

rustls has 4 CVEs on record. 4 were published in the last 90 days. The busiest recent month was September 2026 with 4. The median CVSS is 3.3 (low).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
3.3
Publish → KEV
Last 90 days
4 prev 0

Products

  • webpki 4
4
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

rustls vulnerabilities

CVEs affecting rustls, newest first. Open any entry for full detail, references, and exploit status.

4 CVEsRSS

CVE-2026-93601Low· 2.2
4d ago

rustls-webpki (the Rust webpki fork used by rustls) versions >= 0.101.0 and prior to 0.103.12 and 0.104.0-alpha.6 incorrectly accepted permitted-subtree DNS name constraints for certificates asserting a wildcard name

rustls-webpki (the Rust webpki fork used by rustls) versions >= 0.101.0 and prior to 0.103.12 and 0.104.0-alpha.6 incorrectly accepted permitted-subtree DNS name constraints for certificates asserting a wildcard name. For example, a name…

Sunlitrustls · webpkiEPSS 0.18%via NVD
CVE-2026-93599High· 7.5PoC
4d ago

rustls-webpki through 0.103.12 (and 0.104.0-alpha releases before 0.104.0-alpha.7) contains a reachable panic in bit_string_flags() in src/der.rs

rustls-webpki through 0.103.12 (and 0.104.0-alpha releases before 0.104.0-alpha.7) contains a reachable panic in bit_string_flags() in src/der.rs. The input guard fails to reject a named-bit BIT STRING whose content is exactly [0x00] (ze…

Midnightrustls · webpkiEPSS 0.35%via NVD
CVE-2026-93602Medium· 4.4
4d ago

rustls-webpki versions before 0.103.10 and 0.104.0-alpha.5 contain faulty CRL authority-matching logic that compares only the first distributionPoint against each CRL's IssuingDistributionPoint, ignoring additional distributionPoints

rustls-webpki versions before 0.103.10 and 0.104.0-alpha.5 contain faulty CRL authority-matching logic that compares only the first distributionPoint against each CRL's IssuingDistributionPoint, ignoring additional distributionPoints. At…

Sunlitrustls · webpkiEPSS 0.20%via NVD
CVE-2026-93600Low· 2.2
4d ago

rustls-webpki (rustls/webpki) versions 0.101.0 through 0.103.11 and 0.104.0-alpha releases before 0.104.0-alpha.6 ignore X.509 name constraints that apply to URI names, causing such constraints to be accepted rather than enforced

rustls-webpki (rustls/webpki) versions 0.101.0 through 0.103.11 and 0.104.0-alpha releases before 0.104.0-alpha.6 ignore X.509 name constraints that apply to URI names, causing such constraints to be accepted rather than enforced. Becaus…

Sunlitrustls · webpkiEPSS 0.18%via NVD
rustls vulnerabilities (CVEs) · VulnSea