Vulnerability RUSTSEC-2026-0312

High Risk
HIGH RISK
CVSS Score: 7.4
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
3 days ago
September 24, 2026 at 12:00 PM UTC
Excluded iPAddress name constraints with an all-zero mask are not applied
0.1.0 - 0.3.0
0.1.0 - 0.3.0

Summary

Excluded iPAddress name constraints with an all-zero mask are not applied

Details

An excluded_subtrees iPAddress name constraint with an all-zero mask (0.0.0.0/0 or ::/0) does not restrict iPAddress SANs in certificates issued beneath it. The mask check treated an all-zero mask as matching nothing, when a /0 prefix matches every address of its family, so the exclusion was silently ignored.

CA/Browser Forum Baseline Requirements §7.1.2.5.2 require exactly these exclusions on every technically constrained sub-CA that may not issue for IP addresses. As a result, anyone holding (or having compromised) the key of such a sub-CA can issue a certificate for an arbitrary IP address, and Validator with RFC5280Policy and ServerIdentityPolicy accepts it for that address. A permitted_subtrees dNSName entry on the same issuer does not prevent this, because iPAddress SANs are a different name form.

All users of Validator with RFC5280Policy are affected when a chain can contain a name-constrained issuer with an all-zero iPAddress exclusion.

The issue is fixed in x509-validator 0.3.1 (commit da661f8). Users should upgrade to 0.3.1 or later.

Impacted packages

Timeline

Published
3 days ago
September 24, 2026 at 12:00 PM UTC
Fixed (0.3.1)
3 days ago
September 24, 2026 at 09:42 PM UTC
Last Modified
1 hour ago
September 28, 2026 at 09:45 AM UTC