PT-2026-34530 · Crates.Io · Rustls-Webpki
Published
2026-04-22
·
Updated
2026-04-22
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
A panic was reachable when parsing certificate revocation lists via [
BorrowedCertRevocationList::from der]
or [OwnedCertRevocationList::from der]. This was the result of mishandling a syntactically valid empty
BIT STRING appearing in the onlySomeReasons element of a IssuingDistributionPoint CRL extension.This panic is reachable prior to a CRL's signature being verified.
Applications that do not use CRLs are not affected.
Thank you to @tynus3 for the report.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Rustls-Webpki