Skip to content

fix(deps): bump h2 to fix unbounded empty DATA frames DoS - #118

Closed
SafraNako wants to merge 1 commit into
dfinity:mainfrom
SafraNako:fix/h2-dos-advisory
Closed

SafraNako wants to merge 1 commit into
dfinity:mainfrom
SafraNako:fix/h2-dos-advisory

Conversation

@SafraNako

Copy link
Copy Markdown

What

h2 0.4.150.4.16: RUSTSEC-2026-0258 — a peer could send unbounded empty HTTP/2 DATA frames to exhaust memory/CPU.

Cargo.toml's range already allows 0.4.16, so this is cargo update -p h2 --precise 0.4.16 only — no manifest or source changes.

Verified locally

cargo test --workspace --lib --bins49 tests passed, 0 failed.

Not addressed here

The lockfile also carries rsa 0.9.10, flagged for RUSTSEC-2023-0071 (Marvin Attack — a timing side-channel key-recovery attack). That advisory has no fixed version upstream yet, so there's nothing to bump — a dependency PR can't fix it. Flagging in case rsa is used anywhere timing-sensitive and a maintainer wants to track it separately.

🤖 Generated with Claude Code

h2 0.4.15 -> 0.4.16: RUSTSEC-2026-0258, a peer could send unbounded
empty HTTP/2 DATA frames to exhaust memory/CPU. Cargo.toml range
already allows 0.4.16, so this is `cargo update -p h2 --precise
0.4.16` only -- no manifest changes.

Verified locally: `cargo test --workspace --lib --bins` passes (49 tests).

Not addressed here: the lockfile also has `rsa 0.9.10`, flagged for
RUSTSEC-2023-0071 (Marvin Attack, a timing side-channel). That advisory
has no fixed version yet upstream, so there's nothing to bump -- not
something a dependency PR can fix. Worth a maintainer look if `rsa` is
used for anything timing-sensitive.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@SafraNako
SafraNako requested a review from a team as a code owner September 11, 2026 21:11
@github-actions

Copy link
Copy Markdown

Thank you for contributing! Unfortunately this repository does not accept external contributions yet.

We are working on enabling this by aligning our internal processes and our CI setup to handle external contributions. However this will take some time to set up so in the meantime we unfortunately have to close this Pull Request.

We hope you understand and will come back once we accept external PRs.

— The DFINITY Foundation

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant