{"id":"AZL-103509","summary":"CVE-2026-93601 affecting package rust 1.96.1-2","details":"rustls-webpki (the Rust webpki fork used by rustls) versions \u003e= 0.101.0 and prior to 0.103.12 and 0.104.0-alpha.6 incorrectly accepted permitted-subtree DNS name constraints for certificates asserting a wildcard name. For example, a name constraint of accept.example.com was treated as satisfied by a certificate for *.example.com, which could feasibly assert reject.example.com — a name outside the permitted subtree. Because name constraints are restrictions applied to otherwise properly issued certificates, the issue is only reachable after signature verification succeeds and requires a misissued wildcard certificate to exploit.","modified":"2026-09-26T05:34:12Z","published":"2026-09-18T14:19:11Z","upstream":["CVE-2026-93601"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-93601"}],"affected":[{"package":{"name":"rust","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/rust"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.85.0"},{"last_affected":"1.96.1-2"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-103509.json"}}],"schema_version":"1.9.0"}