CVE-2024-12224

Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
30/05/2025
Last modified:
25/06/2025

Description

Improper Validation of Unsafe Equivalence in punycode by the idna crate from Servo rust-url allows an attacker to create a punycode hostname that one part of a system might treat as distinct while another part of that system would treat as equivalent to another hostname.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:servo:idna:*:*:*:*:*:rust:*:* 1.0.0 (excluding)