216.73.217.22

CVE-2024-12224

· Published 30/05/2025 02:15 · Modified 30/05/2025 16:31

Labels: CVE-2024-12224 2025-05-30CVE-2024-12224CWE-1289[email protected]

Essential information

Published
30/05/2025 02:15
Modified
30/05/2025 16:31
Author
Creator
CVSS
5.1 MEDIUM (v3) 5.1 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Improper Validation of Unsafe Equivalence in punycode by the idna crate from Servo rust-url allows an attacker to create a punycode hostname that one part of a system might treat as distinct while another part of that system would treat as equivalent to another hostname.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
mozilla / idna crate cpe:2.3:a:mozilla:idna_crate:*:*:*:*:*:*:*:*

References