Skip to content

fix(deps): bump rustls to 0.23.45 for RUSTSEC-2026-0285 - #9

Open
ncalvas wants to merge 1 commit into
triton-mainfrom
fix/rustls-rustsec-2026-0285
Open

ncalvas wants to merge 1 commit into
triton-mainfrom
fix/rustls-rustsec-2026-0285

Conversation

@ncalvas

@ncalvas ncalvas commented Oct 8, 2026

Copy link
Copy Markdown
Member

Description

cargo audit fails on RUSTSEC-2026-0285 (published 2026-09-14): rustls 0.23.40 accepts TLS 1.3 handshake messages across encryption level boundaries (5.3, medium). The fix is rustls >= 0.23.45. It showed up on #8, whose change to .github/actions/rust-setup/** triggers the audit workflow, but it fails on any runner.

Lockfile only, made with cargo update -p aws-lc-rs -p rustls-webpki -p rustls:

Crate From To
rustls 0.23.40 0.23.45
aws-lc-rs 1.17.0 1.18.1 (0.23.44+ requires ^1.18)
aws-lc-sys 0.41.0 0.45.0 (pulled by aws-lc-rs)
rustls-webpki 0.103.13 0.103.15 (0.23.44+ requires ^0.103.14)

The other -/+ lines only move some Windows-only dependency entries from windows-sys 0.52.0 to 0.60.2, which was already in the lockfile. cargo update -p rustls --recursive would also have updated serde, syn (adding syn 3), libc and others, so I named the three crates instead.

The other audit entries (bincode, paste, proc-macro-error2, rustybuzz, ttf-parser) are "unmaintained" warnings and don't fail the job.

Checklist

  • The code follows the project's coding conventions and style
  • All tests related to the changes have passed successfully (CI on this PR)
  • Documentation has been updated to reflect the changes (if applicable)
  • All new and existing unit tests have passed (CI on this PR)
  • I have self-reviewed my code and ensured its quality
  • I have added/updated necessary comments to aid understanding

rustls 0.23.40 accepts TLS 1.3 handshake messages across encryption
level boundaries. 0.23.45 needs aws-lc-rs 1.18 and rustls-webpki
0.103.14, so those move with it (aws-lc-sys 0.41 -> 0.45). Nothing else
in the lockfile changes.
@ncalvas ncalvas self-assigned this Oct 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant