fix(deps): bump rustls to 0.23.45 (RUSTSEC-2026-0285) - #37
Merged
Merged
Conversation
The scheduled cargo-deny run has failed since 2026-09-21 on RUSTSEC-2026-0285 (GHSA-2mjx-qc3c-rqvc) in rustls 0.23.41, which reqwest pulls in: TLS 1.3 handshake messages were accepted across encryption level boundaries. `cargo update -p rustls` moves it to the patched 0.23.45 and rustls-webpki to 0.103.15, which 0.23.45 requires (^0.103.14). Cargo.lock only.
|
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## master #37 +/- ##
=======================================
Coverage 86.94% 86.94%
=======================================
Files 33 33
Lines 4941 4941
=======================================
Hits 4296 4296
Misses 645 645 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The scheduled Security workflow (cargo-deny) has failed since 2026-09-21 on unchanged master (4026dcc): run 35598207510, run 36426467663.
Problem
RUSTSEC-2026-0285 / GHSA-2mjx-qc3c-rqvc in
rustls 0.23.41, which comes in transitively (reqwest→hyper-rustls/tokio-rustls). Rustls accepted TLS 1.3 handshake messages across encryption level boundaries, e.g. a plaintextEncryptedExtensionsin the same record asServerHello. The handshake transcript is still authenticated, so an attacker cannot alter or complete a handshake. Fixed in>= 0.23.45. Bans, licenses and sources were clean.The GHSA is not in GitHub's global advisory database (the API answers 404), so Dependabot raised no alert and opened no security PR; only cargo-deny caught it.
Fix
cargo update -p rustls,Cargo.lockonly:rustls0.23.41 → 0.23.45rustls-webpki0.103.13 → 0.103.15 (rustls 0.23.45requires^0.103.14)No manifest or code changes: every requirement in the graph (
reqwest^0.23.4,tokio-rustls^0.23.27,hyper-rustls^0.23) already admits 0.23.45. No new crates; therust_versionof both crates stays 1.71.Verification
cargo deny check: advisories ok, bans ok, licenses ok, sources ok.-D warnings/cargo test --workspace: 301 passed.kaiten -v space liston the test account →GET /spaces200 over HTTPS with rustls 0.23.45.After merge
cargo install --locked kaiten-clistill pin rustls 0.23.41; a patch release ships the fix to them. A plaincargo install kaiten-clialready resolves 0.23.45.@dependabot rebasethem before merging (no lockfile conflicts expected).Release: patch.
🤖 Generated with Claude Code