CVE-2024-12224
Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
30/05/2025
Last modified:
25/06/2025
Description
Improper Validation of Unsafe Equivalence in punycode by the idna crate from Servo rust-url allows an attacker to create a punycode hostname that one part of a system might treat as distinct while another part of that system would treat as equivalent to another hostname.
Impact
Base Score 4.0
5.10
Severity 4.0
MEDIUM
Base Score 3.x
8.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:servo:idna:*:*:*:*:*:rust:*:* | 1.0.0 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



