Improper Validation of Unsafe Equivalence in punycode by the idna crate from Servo rust-url allows an attacker to create a punycode hostname that one part of a system might treat as distinct while another part of that system would treat as equivalent to another hostname.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| idna(crates.io) | 0 | 1.0.0 | N/A |
CVSS Metrics