GothenburgBitFactory / GothenburgBitFactory/taskwarrior
RUSTSEC-2026-0099: Name constraints were accepted for certificates asserting a wildcard name
- Dominant language
- C++
- Stars
- 6.1k
- Forks
- 423
- Avg merge
- 1d 19h
- Merged PRs (30d)
- 11
Description
> Name constraints were accepted for certificates asserting a wildcard name
| Details | |
| ------------------- | ---------------------------------------------- |
| Package | `rustls-webpki` |
| Version | `0.103.10` |
| Date | 2026-04-14 |
| Patched versions | `>=0.103.12, <0.104.0-alpha.1,>=0.104.0-alpha.6` |
Permitted subtree name constraints for DNS names were accepted for certificates asserting a wildcard name.
This was incorrect because, given a name constraint of `accept.example.com`, `*.example.com` could feasibly allow a name of `reject.example.com` which is outside the constraint.
This is very similar to [CVE-2025-61727](https://go.dev/issue/76442).
Since name constraints are restrictions on otherwise properly-issued certificates, this bug is reachable only after signature verification and requires misissuance to exploit.
This vulnerability is identified as [GHSA-xgp8-3hg3-c2mh](https://github.com/rustls/webpki/security/advisories/GHSA-xgp8-3hg3-c2mh). Thank you to @1seal for the report.
See [advisory page](https://rustsec.org/advisories/RUSTSEC-2026-0099.html) for additional details.
Contributor guide
Assessment
This issue has not been assessed yet.