Skip to content

fix(deps): bump rustls to 0.23.45 (RUSTSEC-2026-0285) - #37

Merged
dsociative merged 1 commit into
masterfrom
fix/rustls-rustsec-2026-0285
Sep 29, 2026
Merged

dsociative merged 1 commit into
masterfrom
fix/rustls-rustsec-2026-0285

Conversation

@dsociative

Copy link
Copy Markdown
Owner

The scheduled Security workflow (cargo-deny) has failed since 2026-09-21 on unchanged master (4026dcc): run 35598207510, run 36426467663.

Problem

RUSTSEC-2026-0285 / GHSA-2mjx-qc3c-rqvc in rustls 0.23.41, which comes in transitively (reqwest → hyper-rustls / tokio-rustls). Rustls accepted TLS 1.3 handshake messages across encryption level boundaries, e.g. a plaintext EncryptedExtensions in the same record as ServerHello. The handshake transcript is still authenticated, so an attacker cannot alter or complete a handshake. Fixed in >= 0.23.45. Bans, licenses and sources were clean.

The GHSA is not in GitHub's global advisory database (the API answers 404), so Dependabot raised no alert and opened no security PR; only cargo-deny caught it.

Fix

cargo update -p rustls, Cargo.lock only:

  • rustls 0.23.41 → 0.23.45
  • rustls-webpki 0.103.13 → 0.103.15 (rustls 0.23.45 requires ^0.103.14)

No manifest or code changes: every requirement in the graph (reqwest ^0.23.4, tokio-rustls ^0.23.27, hyper-rustls ^0.23) already admits 0.23.45. No new crates; the rust_version of both crates stays 1.71.

Verification

  • cargo deny check: advisories ok, bans ok, licenses ok, sources ok.
  • fmt / clippy -D warnings / cargo test --workspace: 301 passed.
  • The wiremock tests speak plain HTTP, so TLS was checked live: read-only kaiten -v space list on the test account → GET /spaces 200 over HTTPS with rustls 0.23.45.
  • Independent review: checksums match the crates.io index, neither version is yanked; no Important findings.

After merge

Release: patch.

🤖 Generated with Claude Code

The scheduled cargo-deny run has failed since 2026-09-21 on RUSTSEC-2026-0285
(GHSA-2mjx-qc3c-rqvc) in rustls 0.23.41, which reqwest pulls in: TLS 1.3
handshake messages were accepted across encryption level boundaries.
`cargo update -p rustls` moves it to the patched 0.23.45 and rustls-webpki to
0.103.15, which 0.23.45 requires (^0.103.14). Cargo.lock only.
@codecov-commenter

Copy link
Copy Markdown

⚠️ Please install the 'codecov app svg image' to ensure uploads and comments are reliably processed by Codecov.

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 86.94%. Comparing base (4026dcc) to head (96bf3d2).
❗ Your organization needs to install the Codecov GitHub app to enable full functionality.

Additional details and impacted files
@@           Coverage Diff           @@
##           master      #37   +/-   ##
=======================================
  Coverage   86.94%   86.94%           
=======================================
  Files          33       33           
  Lines        4941     4941           
=======================================
  Hits         4296     4296           
  Misses        645      645           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@dsociative
dsociative merged commit 1a7ff1f into master Sep 29, 2026
9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants