NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
crates.io · #111 most downloaded on crates.io
Web PKI X.509 Certificate Verification.
Last release 1 months ago
21 Aug 2026
Release timing varies
gaps range from 1 weeks to 4 months
Rarely documented
notes for 6 of 36 stable releases
2 versions withdrawn
withdrawn after publishing
4 years old
56 releases · first in 2023
One column per quarter.
Fix reachable panic in parsing a CRL . This was reported to us as GHSA-82j2-j2ch-gfr8 . Users who don't use CRLs are not affected.
Full Changelog: v/0.104.0-alpha.6...v/0.104.0-alpha.7
0.104.0-alpha.7 Pre-release
Pre-release
Compare
Bump version to 0.104.0-alpha.6
Bump version to 0.104.0-alpha.6
This vulnerability is thought to be of limited impact. This is because both the certificate and CRL are signed -- an attacker would need to compromise…
Correct selection of candidate CRLs by Distribution Point and Issuing Distribution Point. If a certificate had more than one distributionPoint, then only the first distributionPoint would be considered against each CRL's IssuingDistributionPoint distributionPoint, and then the certificate's subsequent distributionPoints would be ignored.
The impact was that correct provided CRLs would not be consulted to check revocation. With UnknownStatusPolicy::Deny (the default) this would lead to incorrect but safe Error::UnknownRevocationStatus. With UnknownStatusPolicy::Allow this would lead to inappropriate acceptance of revoked certificates.
This vulnerability is thought to be of limited impact. This is because both the certificate and CRL are signed -- an attacker would need to compromise a trusted issuing authority to trigger this bug. An attacker with such capabilities could likely bypass revocation checking through other more impactful means (such as publishing a valid, empty CRL.)
More likely, this bug would be latent in normal use, and an attacker could leverage faulty revocation checking to continue using a revoked credential.
This vulnerability is identified by GHSA-pwjx-qhcg-rvj4. Thank you to @1seal for the report.
Full Changelog: v/0.104.0-alpha.4...v/0.104.0-alpha.5
0.104.0-alpha.5 Pre-release
Pre-release
Compare
tests: port client auth revocation tests to Rust by @djc in #442
0.104.0-alpha.4 Pre-release
Pre-release
Compare
0.104.0-alpha.3 Pre-release Pre-release Compare # Choose a tag to compare
0.104.0-alpha.3 Pre-release
Pre-release
Compare
Nothing published for this version
Nothing published for this version
Cargo: avoid all-features in docs.rs by @cpu in #530
Fixes docs.rs build errors.
Full Changelog: https://github.com/rustls/webpki/compare/v/0.103.14..v/0.103.15
[0.103] Support stable ML-DSA by @djc in #523
Full Changelog: v/0.103.13...v/0.103.14
Fix reachable panic in parsing a CRL . This was reported to us as GHSA-82j2-j2ch-gfr8 . Users who don't use CRLs are not affected.
Full Changelog: v/0.103.12...v/0.103.13
…outside the constraint. This is very similar to CVE-2025-61727 .
This release fixes two bugs in name constraint enforcement:
accept.example.com, *.example.com could feasibly allow a name of reject.example.com which is outside the constraint. This is very similar to CVE-2025-61727.Since name constraints are restrictions on otherwise properly-issued certificates, these bugs are reachable only after signature verification and require misissuance to exploit.
Full Changelog: v/0.103.11...v/0.103.12
In response to #464 , we've slightly relaxed requirements for anchor_from_trust_cert() to ignore unknown extensions even if they're marked as critical
In response to #464, we've slightly relaxed requirements for anchor_from_trust_cert() to ignore unknown extensions even if they're marked as critical. This only affects parsing a TrustAnchor from DER, for which most extensions are ignored anyway.
This vulnerability is thought to be of limited impact. This is because both the certificate and CRL are signed -- an attacker would need to compromise…
Correct selection of candidate CRLs by Distribution Point and Issuing Distribution Point. If a certificate had more than one distributionPoint, then only the first distributionPoint would be considered against each CRL's IssuingDistributionPoint distributionPoint, and then the certificate's subsequent distributionPoints would be ignored.
The impact was that correctly provided CRLs would not be consulted to check revocation. With UnknownStatusPolicy::Deny (the default) this would lead to incorrect but safe Error::UnknownRevocationStatus. With UnknownStatusPolicy::Allow this would lead to inappropriate acceptance of revoked certificates.
This vulnerability is thought to be of limited impact. This is because both the certificate and CRL are signed -- an attacker would need to compromise a trusted issuing authority to trigger this bug. An attacker with such capabilities could likely bypass revocation checking through other more impactful means (such as publishing a valid, empty CRL.)
More likely, this bug would be latent in normal use, and an attacker could leverage faulty revocation checking to continue using a revoked credential.
This vulnerability is identified by GHSA-pwjx-qhcg-rvj4. Thank you to @1seal for the report.
Full Changelog: v/0.103.9...v/0.103.10
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →