FuelLabs / FuelLabs/data-systems
RUSTSEC-2026-0099: Name constraints were accepted for certificates asserting a wildcard name
- Dominant language
- Rust
- Stars
- 18
- Forks
- 18
- PR merge metrics
- No merged PRs in 30d
Description
> Name constraints were accepted for certificates asserting a wildcard name
| Details | |
| ------------------- | ---------------------------------------------- |
| Package | `rustls-webpki` |
| Version | `0.101.7` |
| Date | 2026-04-14 |
| Patched versions | `>=0.103.12, <0.104.0-alpha.1,>=0.104.0-alpha.6` |
Permitted subtree name constraints for DNS names were accepted for certificates asserting a wildcard name.
This was incorrect because, given a name constraint of `accept.example.com`, `*.example.com` could feasibly allow a name of `reject.example.com` which is outside the constraint.
This is very similar to [CVE-2025-61727](https://go.dev/issue/76442).
Since name constraints are restrictions on otherwise properly-issued certificates, this bug is reachable only after signature verification and requires misissuance to exploit.
This vulnerability is identified as [GHSA-xgp8-3hg3-c2mh](https://github.com/rustls/webpki/security/advisories/GHSA-xgp8-3hg3-c2mh). Thank you to @1seal for the report.
See [advisory page](https://rustsec.org/advisories/RUSTSEC-2026-0099.html) for additional details.
Contributor guide
Research direction
Start with the linked GHSA advisory and advisory page to understand the affected rustls-webpki versions and patched ranges. The issue names no repository file, test, or entry point, so locate how the dependency is used before proposing work. Done cannot be confirmed from this issue alone; maintainers should define the required update or regression test.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- rust
- Domain
- security
- Issue type
- Bug
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Quiet
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100