Bug 2538656 (CVE-2026-93601)

Summary: CVE-2026-93601 rustls-webpki: rustls-webpki: Name Constraint Bypass in wildcard certificate validation
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedCC: akhatavk, anpicker, anthomas, aos-team-art-private, aprice, asdas, bbrownin, blitton, bparees, brasmith, cochase, dbosanac, doconnor, dpaolell, dranck, dschmidt, eborisov, ehelms, gbenhaim, ggainey, gotiwari, hasun, hoberger, jcantril, jdelft, jfula, jhorak, jlanda, jowilson, jpasqual, jreimann, jsamir, jupierce, juwatts, kshier, lball, lgarciaa, lpele, mbarnett, mbiarnes, mdellweg, mdessi, mhulan, mrizzi, mvyas, ngough, niyer, nmoumoul, nyancey, oezr, ometelka, osousa, pcattana, pcreech, ppalepu, ppostler, prdhamdh, ptisnovs, rchan, rekumar, rhel-process-autobot, rjohnson, rojacob, sarad, sghai, sidsharm, simaishi, smallamp, sprizend, stcannon, suppawar, syedriko, tmalecek, twaugh, veshanka, vlaad, vvoronko, watson-tool-maintainers, xdharmai, yguenane
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in rustls-webpki. This component incorrectly processes DNS (Domain Name System) name constraints for certificates asserting a wildcard name. This could allow a misissued wildcard certificate to be accepted for a domain that should be outside its permitted scope. Consequently, this bypass of name constraints could lead to incorrect certificate validation, potentially enabling an attacker to spoof a legitimate domain or perform man-in-the-middle attacks if they can obtain and use such a misissued certificate.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-09-22 19:53:40 UTC
rustls-webpki (the Rust webpki fork used by rustls) versions >= 0.101.0 and prior to 0.103.12 and 0.104.0-alpha.6 incorrectly accepted permitted-subtree DNS name constraints for certificates asserting a wildcard name. For example, a name constraint of accept.example.com was treated as satisfied by a certificate for *.example.com, which could feasibly assert reject.example.com — a name outside the permitted subtree. Because name constraints are restrictions applied to otherwise properly issued certificates, the issue is only reachable after signature verification succeeds and requires a misissued wildcard certificate to exploit.