Intel

AIKIDO-2026-714787

x509-validator is vulnerable to Improper Certificate Validation

Improper Certificate ValidationGHSA-39mm-4q6x-3vrx Published Yesterday

74

High Risk

This Affects:

RUSTx509-validator
0.1.0 - 0.3.0
Fixed in 0.3.1
Are you affected? Scan for Free

TL;DR

The iPAddress exclusion check treats an excluded_subtrees constraint whose mask is all zeros (0.0.0.0/0 or ::/0) as matching nothing. A /0 prefix matches every address of that family, so the exclusion is ignored. A technically constrained sub-CA that must not issue for IP addresses can still issue a certificate for an arbitrary IP, and Validator with RFC5280Policy and ServerIdentityPolicy accepts it for that address. A permitted_subtrees dNSName entry on the same issuer does not stop this, because an iPAddress SAN is a different name form. The fix treats an all-zero mask as matching every address of its family.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you validate chains with Validator and RFC5280Policy that can include a name-constrained issuer with an all-zero iPAddress exclusion.

Background info

x509-validator is vulnerable to Improper Certificate Validation in versions 0.1.0 - 0.3.0.

How to fix this

Upgrade the x509-validator library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform