Skip to content

chore: bump h2 to 0.4.16 for RUSTSEC-2026-0258 - #4173

Draft
kdeforth-bot wants to merge 1 commit into
near:mainfrom
kdeforth-bot:kd/bump-h2-rustsec-2026-0258
Draft

chore: bump h2 to 0.4.16 for RUSTSEC-2026-0258#4173
kdeforth-bot wants to merge 1 commit into
near:mainfrom
kdeforth-bot:kd/bump-h2-rustsec-2026-0258

Conversation

@kdeforth-bot

Copy link
Copy Markdown

h2 0.4.14 is affected by RUSTSEC-2026-0258 (unbounded empty DATA frames), assigned 2026-08-18. Empty DATA frames can be queued without bound for a stream that is not actively drained, leading to unbounded memory usage or a panic if the length overflows. Low severity, patched in 0.4.16.

cargo make check-extra currently fails on main with:

error[vulnerability]: h2 unbounded empty DATA frames
  ┌─ Cargo.lock:343:1
343 │ h2 0.4.14 registry+https://github.com/rust-lang/crates.io-index
      Patched in v0.4.16.
advisories FAILED

Lockfile-only (cargo update -p h2): exactly one package changes, 302 dependencies untouched. The last dependabot group bump (#4164) merged before the advisory was assigned, so it did not pick this up.

Verified locally: cargo deny --all-features checkadvisories ok, bans ok, licenses ok, sources ok.

🤖 Generated with Claude Code

`h2` 0.4.14 is affected by RUSTSEC-2026-0258 (unbounded empty DATA
frames): empty DATA frames can be queued without bound for a stream that
is not actively drained, leading to unbounded memory usage or a panic if
the length overflows. Low severity, patched in 0.4.16.

Lockfile-only; no other package changes.
@kevindeforth
kevindeforth marked this pull request as draft August 18, 2026 14:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants