Improper Validation of Unsafe Equivalence in punycode by the idna crate from Servo rust-url allows an attacker to create a punycode hostname that one part of a system might treat as distinct while another part of that system would treat as equivalent to another hostname.
CVSS Details
- CVSS 4.0 Base Score: 5.1 (MEDIUM)
- CVSS 4.0 Vector: (CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-cargo-modules | Aug 8, 2025 | May 30, 2025 | |
| Debian | no-fix-debian-deb-package | May 15, 2025 | May 15, 2025 | |
| Redhat_linux | — | no-fix-redhat-rpm-package | Jul 9, 2025 | May 30, 2025 |
| Suse | — | suse-upgrade-aws-nitro-enclaves-binaryblobs-upstreamsuse-upgrade-aws-nitro-enclaves-clisuse-upgrade-keylime-ima-policysuse-upgrade-librav1e0_6suse-upgrade-librav1e0_6-32bitsuse-upgrade-python313-nh3suse-upgrade-rav1esuse-upgrade-rav1e-develsuse-upgrade-rust-keylimesuse-upgrade-rustupsuse-upgrade-sccachesuse-upgrade-sevctlsuse-upgrade-snpguestsuse-upgrade-system-group-ne | Dec 5, 2025 | Jul 2, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub