PT-2026-34530 · Crates.Io · Rustls-Webpki

Published

2026-04-22

·

Updated

2026-04-22

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
A panic was reachable when parsing certificate revocation lists via [BorrowedCertRevocationList::from der] or [OwnedCertRevocationList::from der]. This was the result of mishandling a syntactically valid empty BIT STRING appearing in the onlySomeReasons element of a IssuingDistributionPoint CRL extension.
This panic is reachable prior to a CRL's signature being verified.
Applications that do not use CRLs are not affected.
Thank you to @tynus3 for the report.

Related Identifiers

RUSTSEC-2026-0104

Affected Products

Rustls-Webpki