Skip to content

fix(deps): rustls 0.23.45 — RUSTSEC-2026-0285 - #193

Merged
jamesyong-42 merged 1 commit into
mainfrom
fix/rustls-rustsec-2026-0285
Sep 16, 2026
Merged

jamesyong-42 merged 1 commit into
mainfrom
fix/rustls-rustsec-2026-0285

Conversation

@jamesyong-42

@jamesyong-42 jamesyong-42 commented Sep 16, 2026 •

Copy link
Copy Markdown
Member

cargo-deny fails on main and every PR since RUSTSEC-2026-0285 (rustls < 0.23.45, TLS 1.3 handshake messages accepted across encryption level boundaries). Lockfile-only: the workspace requirement is 0.23; cargo update -p rustls --precise 0.23.45 (cargo's default pick, 0.23.43, is still inside the advisory).

🤖 Generated with Claude Code

https://claude.ai/code/session_01EKZYYSoZPAXbaw1CYULNKW


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

…ages across encryption levels)

cargo-deny's advisory check reddened every PR and main itself the day RUSTSEC-2026-0285
was published: rustls 0.23.38 accepts TLS 1.3 handshake messages across encryption
level boundaries (GHSA-2mjx-qc3c-rqvc); the fix is >=0.23.45. Lockfile-only: the
workspace requirement is `0.23`, and `cargo update -p rustls --precise 0.23.45` moves
the one entry (cargo's default pick was 0.23.43, still inside the advisory).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EKZYYSoZPAXbaw1CYULNKW
@jamesyong-42
jamesyong-42 merged commit ff1bbd6 into main Sep 16, 2026
13 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant