Skip to content

Update rustls to fix TLS handshake validation #1002

Description

@sehkone

Problem

The current lockfile resolves rustls 0.23.44, affected by RUSTSEC-2026-0285 / GHSA-2mjx-qc3c-rqvc. Rustls can accept TLS 1.3 handshake messages across encryption-level boundaries when messages share a record. Upstream fixes this in 0.23.45; the affected range is 0.23.13 through 0.23.44.

The advisory makes cargo audit fail in PR #1001's CI, preventing the dependent unit/CLI and Docker E2E jobs from running. Prioritize this security update before the independent Dependabot grouping PR #1001.

Scope and acceptance criteria

  • Update the resolved rustls version to 0.23.45, the patched release, using a targeted Cargo update. The existing Cargo.toml constraint 0.23 already permits it.
  • Keep unrelated dependencies and application behavior unchanged. Include additional lockfile changes only if required by resolution of the patched release.
  • Add a concise security changelog entry describing the corrected TLS handshake validation, since the last released version also carries affected rustls code.
  • Preserve certificate verification, TLS policies, and existing audit checks. Do not suppress the advisory or weaken CI.
  • Keep this change independent of the Dependabot grouping configuration in Correct Dependabot dependency grouping #1001. Open a linked PR against main; do not merge it.

Validation

  • Confirm the lockfile resolves the patched version and inspect the dependency diff.
  • Run cargo audit and confirm RUSTSEC-2026-0285 no longer appears as a vulnerability.
  • Run the repository quality checks and local preflight, including the Docker E2E matrix. If a local environmental prerequisite blocks the matrix, run as far as possible and document the exact local results and limitation, leaving CI to gate the remaining coverage under AGENTS.md.
  • Require the PR's Quality Check, unit/CLI tests, Docker E2E matrix, and CodeQL checks to finish successfully before handoff.

After this PR is merged by a maintainer, bring its fix into #1001 and rerun that PR's CI as the lower-priority follow-up.

No activity

Activity on this issue will appear here.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions