bitcoindevkit / bitcoindevkit/bdk-cli

RUSTSEC-2026-0098: Name constraints for URI names were incorrectly accepted

Open
#286 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Rust
Stars
141
Forks
99
Avg merge
6d 14m
Merged PRs (30d)
1

Description

| Details | |
| --- | --- |
| Package | `rustls-webpki` |
| Version | `0.101.7` |
| URL | n/a |
| Patched Versions | >=0.103.12, <0.104.0-alpha.1 OR >=0.104.0-alpha.6 |
| Aliases | [GHSA-965h-392x-2mh5](https://github.com/advisories/GHSA-965h-392x-2mh5) |

Name constraints for URI names were ignored and therefore accepted.

Note this library does not provide an API for asserting URI names, and URI name constraints are otherwise not implemented. URI name constraints are now rejected unconditionally.

Since name constraints are restrictions on otherwise properly-issued certificates, this bug is reachable only after signature verification and requires misissuance to exploit.

This vulnerability is identified as [GHSA-965h-392x-2mh5](https://github.com/rustls/webpki/security/advisories/GHSA-965h-392x-2mh5). Thank you to [@1seal](https://github.com/1seal) for the report.

Contributor guide

Open the contributing guide

Research direction

Review how the repository declares the rustls-webpki dependency and compare its version with the patched versions listed in this issue. Start by checking the dependency metadata and existing validation tests; done means the vulnerable 0.101.7 release is no longer selected and the relevant checks pass.

Written by the indexing model from the issue text.

Assessment

Tech stack
rust
Domain
cryptography, security
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.