Skip to content

Bump rustls to 0.23.45 for RUSTSEC-2026-0285 - #262

Merged
mike1858 merged 1 commit into
mainfrom
chore/fix-rustls-advisory
Sep 22, 2026
Merged

mike1858 merged 1 commit into
mainfrom
chore/fix-rustls-advisory

Conversation

@mike1858

@mike1858 mike1858 commented Sep 22, 2026 •

Copy link
Copy Markdown
Member

Why

cargo audit is a required status check on main, and it has been failing on main itself since #258 landed (run 35634534809 on 2be34c6). The failure has nothing to do with #258's diff: the RustSec advisory database published RUSTSEC-2026-0285 against rustls in the meantime, and Splitrail's lockfile pins rustls 0.23.36.

RUSTSEC-2026-0285 — TLS 1.3 handshake messages incorrectly accepted across encryption level boundaries. Solution: upgrade to >=0.23.45.
https://rustsec.org/advisories/RUSTSEC-2026-0285

Because the check is required, every open PR fails it no matter what it changes, and no release PR can merge until main is fixed. rustls is on Splitrail's real network path: reqwest uses it for the cloud upload client, so this is not a feature-gated false positive of the kind already documented in .cargo/audit.toml.

What changed

A lockfile-only bump. Cargo.toml is untouched.

Crate Before After
rustls 0.23.36 0.23.45
rustls-webpki 0.103.13 0.103.15
aws-lc-rs 1.16.2 1.18.1
aws-lc-sys 0.39.1 0.45.0

The aws-lc-* bump is required, not incidental. A plain cargo update -p rustls updates only rustls and stops at 0.23.43, because 0.23.44 and later need a newer aws-lc-rs than the lockfile allows. Reaching the fixed version means moving the crypto backend with it, so this PR pins with cargo update -p rustls --precise 0.23.45. All four crates declare rust-version = 1.71, well below the nightly toolchain in rust-toolchain.toml.

Risk

aws-lc-sys compiles a C library, which makes platform coverage the real risk in this bump. The PR's Test (windows-latest) job covers the MSVC build. PR CI never builds the release workflow's cross-compiled Linux targets (aarch64/x86_64 × gnu/musl), so all four were built locally with cross 0.2.5 in isolated target directories; see Validation.

Not changed

The remaining two advisories are unsoundness warnings, which cargo audit reports without failing, and this PR leaves them alone:

  • RUSTSEC-2026-0190 (anyhow, Error::downcast_mut())
  • RUSTSEC-2026-0253 (lru, LruCache::pop() panic safety)

Validation

  • cargo audit → exit 0 (was: error: 1 vulnerability found!)
  • cargo build --quiet
  • cargo test --quiet
  • cargo clippy --quiet --all-targets -- -D warnings
  • cross build --release --locked --target <t> for aarch64-unknown-linux-musl, aarch64-unknown-linux-gnu, x86_64-unknown-linux-gnu, x86_64-unknown-linux-musl: all four finished and produced ELF binaries of the right architecture

@coderabbitai

coderabbitai Bot commented Sep 22, 2026

Copy link
Copy Markdown

Important

Review skipped

Review was skipped due to path filters

⛔ Files ignored due to path filters (1)
  • Cargo.lock is excluded by !**/*.lock

CodeRabbit blocks several paths by default. You can override this behavior by explicitly including those paths in the path filters. For example, including **/dist/** will override the default block on the dist directory, by removing the pattern from both the lists.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: b637bed6-15fc-4c6e-9d79-54b559e4b435

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@mike1858
mike1858 merged commit 3d479f9 into main Sep 22, 2026
8 checks passed
@mike1858
mike1858 deleted the chore/fix-rustls-advisory branch September 22, 2026 16:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant