RUSTSEC-2026-0312

Source
https://rustsec.org/advisories/RUSTSEC-2026-0312
Import Source
https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2026-0312.json
JSON Data
https://api.osv.dev/v1/vulns/RUSTSEC-2026-0312
Aliases
  • GHSA-39mm-4q6x-3vrx
Published
2026-09-24T12:00:00Z
Modified
2026-09-28T09:45:02Z
Severity
  • 7.4 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
Excluded iPAddress name constraints with an all-zero mask are not applied
Details

An excluded_subtrees iPAddress name constraint with an all-zero mask (0.0.0.0/0 or ::/0) does not restrict iPAddress SANs in certificates issued beneath it. The mask check treated an all-zero mask as matching nothing, when a /0 prefix matches every address of its family, so the exclusion was silently ignored.

CA/Browser Forum Baseline Requirements ยง7.1.2.5.2 require exactly these exclusions on every technically constrained sub-CA that may not issue for IP addresses. As a result, anyone holding (or having compromised) the key of such a sub-CA can issue a certificate for an arbitrary IP address, and Validator with RFC5280Policy and ServerIdentityPolicy accepts it for that address. A permitted_subtrees dNSName entry on the same issuer does not prevent this, because iPAddress SANs are a different name form.

All users of Validator with RFC5280Policy are affected when a chain can contain a name-constrained issuer with an all-zero iPAddress exclusion.

The issue is fixed in x509-validator 0.3.1 (commit da661f8). Users should upgrade to 0.3.1 or later.

Database specific
{
    "license":  "CC0-1.0"
}
References

Affected packages

crates.io / x509-validator

Package

Name
x509-validator
View open source insights on deps.dev
Purl
pkg:cargo/x509-validator

Affected ranges

Type
SEMVER
Events
Introduced
0.0.0-0
Fixed
0.3.1

Ecosystem specific

{
    "affected_functions":  null,
    "affects":  {
        "arch":  [],
        "functions":  [],
        "os":  []
    }
}

Database specific

categories
[
    "crypto-failure"
]
cvss
"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
informational
null
source
"https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2026-0312.json"