Skip to content

chore(deps): bump rustls to 0.23.45 (GHSA-2mjx-qc3c-rqvc) - #124

Merged
jpage-godaddy merged 1 commit into
mainfrom
rustls-vuln
Oct 8, 2026
Merged

jpage-godaddy merged 1 commit into
mainfrom
rustls-vuln

Conversation

@jpage-godaddy

Copy link
Copy Markdown
Collaborator

Summary

Fixes Dependabot alert #2 (GHSA-2mjx-qc3c-rqvc, medium): rustls >= 0.23.13, < 0.23.45 accepts TLS 1.3 handshake messages across encryption level boundaries.

  • rustls 0.23.40 → 0.23.45 (patched)
  • rustls-webpki 0.103.13 → 0.103.15 (rustls 0.23.44+ requires ^0.103.14)
  • tempfile now resolves getrandom 0.3.4 instead of 0.4.2 (cargo re-resolution side effect; dev/test tooling only)

Cargo.lock only. rustls is a transitive dependency via reqwest, and every dependent's requirement (^0.23, ^0.23.4, ^0.23.27) already allows 0.23.45, so no manifest changes were needed.

Why not Dependabot

The Dependabot security job failed with security_update_not_possible (latest-resolvable 0.23.43, no conflicting dependencies). 0.23.43 is the last rustls compatible with the locked rustls-webpki 0.103.13, and Dependabot did not move that second crate. cargo update -p rustls --precise 0.23.45 resolves both together.

Test plan

  • cargo clippy --all-targets -- -D warnings
  • cargo test --all-targets
  • CI

🤖 Generated with Claude Code

rustls < 0.23.45 accepts TLS 1.3 handshake messages across encryption
level boundaries. rustls is a transitive dependency via reqwest, so this
is a lockfile-only update; every dependent's version requirement already
allows 0.23.45.

rustls-webpki moves from 0.103.13 to 0.103.15 because rustls 0.23.44+
requires ^0.103.14. Dependabot could not resolve the two together
(security_update_not_possible, capped at 0.23.43).

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
@jpage-godaddy
jpage-godaddy merged commit ede59ca into main Oct 8, 2026
3 checks passed
@jpage-godaddy
jpage-godaddy deleted the rustls-vuln branch October 8, 2026 18:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant