{"id":"CVE-2024-12224","aliases":["GHSA-h97m-ww89-6jmq","RUSTSEC-2024-0421"],"url":"https://o3.security/vulnerability/CVE-2024-12224","summary":"idna accepts Punycode labels that do not produce any non-ASCII when decoded","details":"Improper Validation of Unsafe Equivalence in punycode by the idna crate from Servo rust-url allows an attacker to create a punycode hostname that one part of a system might treat as distinct while another part of that system would treat as equivalent to another hostname.","published":"2025-05-30T01:16:47.829Z","modified":"2026-07-28T18:30:19.231255268Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"idna","fixedVersion":"1.0.0"}],"fix":null,"references":[{"type":"WEB","url":"https://crates.io/crates/idna"},{"type":"WEB","url":"https://github.com/servo/rust-url/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/12xxx/CVE-2024-12224.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-12224"},{"type":"ADVISORY","url":"https://rustsec.org/advisories/RUSTSEC-2024-0421.html"},{"type":"REPORT","url":"https://bugzilla.mozilla.org/show_bug.cgi?id=1887898"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-28T18:30:19.231255268Z"}}