Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-3478 | Improper Validation of Unsafe Equivalence in punycode by the idna crate from Servo rust-url allows an attacker to create a punycode hostname that one part of a system might treat as distinct while another part of that system would treat as equivalent to another hostname. |
Github GHSA |
GHSA-h97m-ww89-6jmq | `idna` accepts Punycode labels that do not produce any non-ASCII when decoded |
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 25 Jun 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Servo
Servo idna |
|
| Weaknesses | CWE-352 | |
| CPEs | cpe:2.3:a:servo:idna:*:*:*:*:*:rust:*:* | |
| Vendors & Products |
Servo
Servo idna |
|
| Metrics |
cvssV3_1
|
cvssV3_1
|
Fri, 30 May 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Fri, 30 May 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 30 May 2025 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Validation of Unsafe Equivalence in punycode by the idna crate from Servo rust-url allows an attacker to create a punycode hostname that one part of a system might treat as distinct while another part of that system would treat as equivalent to another hostname. | |
| Title | idna accepts Punycode labels that do not produce any non-ASCII when decoded | |
| Weaknesses | CWE-1289 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: mozilla
Published:
Updated: 2025-05-30T12:46:56.887Z
Reserved: 2024-12-05T02:50:17.716Z
Link: CVE-2024-12224
Updated: 2025-05-30T12:46:47.514Z
Status : Analyzed
Published: 2025-05-30T02:15:19.670
Modified: 2025-06-25T15:33:17.667
Link: CVE-2024-12224
OpenCVE Enrichment
No data.
EUVD
Github GHSA