Skip to content

Bump rustls to 0.23.45 (RUSTSEC-2026-0285) - #2

Merged
mattpodwysocki merged 1 commit into
mainfrom
fix/rustls-rustsec-2026-0285
Sep 14, 2026
Merged

mattpodwysocki merged 1 commit into
mainfrom
fix/rustls-rustsec-2026-0285

Conversation

@zmofei

@zmofei zmofei commented Sep 14, 2026

Copy link
Copy Markdown
Member

Fixes RUSTSEC-2026-0285: TLS 1.3 handshake messages were incorrectly accepted across encryption level boundaries in rustls <0.23.45. Blocks cargo-audit in downstream CI (mapbox-cli-private).

TLS 1.3 handshake messages were incorrectly accepted across
encryption level boundaries in rustls <0.23.45.

@mattpodwysocki mattpodwysocki left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approving, and this should go in ahead of #3–#7 — all five are red on nothing but this advisory.

Verified independently rather than by reading the version number. I had reached for the same fix before spotting this PR, so there are now two derivations of it, and they are byte-identical: cargo update -p rustls on a clean checkout produces a Cargo.lock with the same sha256 as this branch's (15acf898…). Same version, same checksum, nothing else touched.

And with the tool CI uses:

Lockfile cargo audit --file
this branch 207 crate dependencies scanned, nothing reported
main, as a control error: 1 vulnerability found! — RUSTSEC-2026-0285

The control is the part worth having: it shows the bump is what clears it, and that no second advisory is hiding behind the first.

Right shape of fix, too — lockfile only, well inside the range reqwest already declares, so no manifest edit and no semver decision for a transitive dependency.

I'm closing my #9 as the duplicate. Two follow-ups once this lands: #6 (rand 0.10) is the only one of my five that also touches Cargo.lock, so it needs a trivial rebase and I'll do it; and mapbox-cli-private's main is red on this same advisory through the oss/ submodule, so its pin wants advancing to pick this up.

@mattpodwysocki
mattpodwysocki merged commit a4fb834 into main Sep 14, 2026
8 checks passed
@mattpodwysocki
mattpodwysocki deleted the fix/rustls-rustsec-2026-0285 branch September 14, 2026 17:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants