We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-12224

idna accepts Punycode labels that do not produce any non-ASCII when decoded



Description

Improper Validation of Unsafe Equivalence in punycode by the idna crate from Servo rust-url allows an attacker to create a punycode hostname that one part of a system might treat as distinct while another part of that system would treat as equivalent to another hostname.

Reserved 2024-12-05 | Published 2025-05-30 | Updated 2025-05-30 | Assigner mozilla


MEDIUM: 5.1CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:L/SA:N

Problem types

CWE-1289

Product status

Default status
unaffected

Any version before 1.0.0
affected

References

rustsec.org/advisories/RUSTSEC-2024-0421.html vendor-advisory

bugzilla.mozilla.org/show_bug.cgi?id=1887898 issue-tracking

cve.org (CVE-2024-12224)

nvd.nist.gov (CVE-2024-12224)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2024-12224

Support options

Helpdesk Chat, Email, Knowledgebase