RUSTSEC-2023-0053

    Dashboard / Vulnerabilities / RUSTSEC-2023-0053

    RUSTSEC-2023-0053

    Published: 22 Aug 2023Last Modified: 4 Feb 2026

    Summary: rustls-webpki: CPU denial of service in certificate path building

    Details: When this crate is given a pathological certificate chain to validate, it will spend CPU time exponential with the number of candidate certificates at each step of path building. Both TLS clients and TLS servers that accept client certificate are affected. We now give each path building operation a budget of 100 signature verifications. The original `webpki` crate is also affected. This was previously reported in the original crate <https://github.com/briansmith/webpki/issues/69> and re-reported to us recently by Luke Malinowski.

    Affected packages

    Package

    Name: rustls-webpki

    Purl: pkg:cargo/rustls-webpki

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0.0.0-0
    Fixed -0.100.2

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High