Bump rustls to 0.23.45 (RUSTSEC-2026-0285) - #2
Conversation
TLS 1.3 handshake messages were incorrectly accepted across encryption level boundaries in rustls <0.23.45.
mattpodwysocki
left a comment
There was a problem hiding this comment.
Approving, and this should go in ahead of #3–#7 — all five are red on nothing but this advisory.
Verified independently rather than by reading the version number. I had reached for the same fix before spotting this PR, so there are now two derivations of it, and they are byte-identical: cargo update -p rustls on a clean checkout produces a Cargo.lock with the same sha256 as this branch's (15acf898…). Same version, same checksum, nothing else touched.
And with the tool CI uses:
| Lockfile | cargo audit --file |
|---|---|
| this branch | 207 crate dependencies scanned, nothing reported |
main, as a control |
error: 1 vulnerability found! — RUSTSEC-2026-0285 |
The control is the part worth having: it shows the bump is what clears it, and that no second advisory is hiding behind the first.
Right shape of fix, too — lockfile only, well inside the range reqwest already declares, so no manifest edit and no semver decision for a transitive dependency.
I'm closing my #9 as the duplicate. Two follow-ups once this lands: #6 (rand 0.10) is the only one of my five that also touches Cargo.lock, so it needs a trivial rebase and I'll do it; and mapbox-cli-private's main is red on this same advisory through the oss/ submodule, so its pin wants advancing to pick this up.
Fixes RUSTSEC-2026-0285: TLS 1.3 handshake messages were incorrectly accepted across encryption level boundaries in rustls <0.23.45. Blocks
cargo-auditin downstream CI (mapbox-cli-private).