Improper Validation of Unsafe Equivalence in punycode by the idna crate from Servo rust-url allows an attacker to create a punycode hostname that one part of a system might treat as distinct while another part of that system would treat as equivalent to another hostname.
Exploitability
AV:NAC:HAT:PPR:LUI:NVulnerable System
VC:NVI:NVA:NSubsequent System
SC:HSI:LSA:N5.1/CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:L/SA:NOther