An open index of dependabot pull requests across open source projects.

rustls-webpki

Ecosystem:
cargo
Package URL:
pkg:cargo/rustls-webpki
Total PRs:
714 Dependabot PRs
Latest PR:
about 7 hours ago
Unique Repositories:
489 repositories
Unique Repos (30 days):
29 repositories
Security Advisories
webpki: Name constraints were accepted for certificates asserting a wildcard name
GHSA-xgp8-3hg3-c2mh LOW published about 2 months ago • updated 16 days ago
Permitted subtree name constraints for DNS names were accepted for certificates asserting a wildcard name. This was incorrect because, given a nam...
rustls-webpki: Denial of service via panic on malformed CRL BIT STRING
GHSA-82j2-j2ch-gfr8 HIGH published about 1 month ago • updated 17 days ago
### Summary `bit_string_flags()` in `src/der.rs` panics with an index-out-of-bounds when given a BIT STRING whose content is exactly `[0x00]` (one...
webpki: Name constraints for URI names were incorrectly accepted
GHSA-965h-392x-2mh5 LOW published about 2 months ago • updated about 2 months ago
Name constraints for URI names were ignored and therefore accepted. Note this library does not provide an API for asserting URI names, and URI nam...
webpki: CRLs not considered authoritative by Distribution Point due to faulty matching logic
GHSA-pwjx-qhcg-rvj4 MODERATE published 3 months ago • updated about 2 hours ago
If a certificate had more than one `distributionPoint`, then only the first `distributionPoint` would be considered against each CRL's `IssuingDist...
rustls-webpki: CPU denial of service in certificate path building
GHSA-fh2r-99q2-6mmg HIGH published almost 3 years ago • updated 3 days ago
When this crate is given a pathological certificate chain to validate, it will spend CPU time exponential with the number of candidate certificates...
Recent PRs
Bump rustls-webpki from 0.103.11 to 0.103.13

anttiharju/slack9 #14

0.103.11 → 0.103.13 Patch PR
Closed about 1 month ago 3 comments
anttiharju
Package Details
Name: rustls-webpki
Ecosystem: cargo
PURL Type: cargo
Package URL: pkg:cargo/rustls-webpki
JSON API: View JSON
Security Advisories

5

Active advisories
HIGH 2
MODERATE 1
LOW 2
View All cargo Advisories
Package Information
Description:

Web PKI X.509 Certificate Verification.

Repository: https://github.com/rustls/webpki
Latest Release: 0.103.3
about 1 year ago
Dependent Repos: 4,654
Dependent Packages: 65
Downloads: 192,808,216
Ranking: Top 0.5205% by dependent repos Top 0.2842% by downloads Top 1.0233% by dependent pkgs
PR Status
Open 258 (36.1%)
Merged 58 (8.1%)
Closed 391 (54.8%)
PR Types
Minor 7 (1.0%)
Patch 700 (98.0%)