Skip to content

Fix Dependabot alerts: openssl 0.10.80, serde_with 3.21.0, h2 0.4.18 - #2104

Open
erubboli wants to merge 1 commit into
masterfrom
dependabot_openssl_serde_with
Open

Fix Dependabot alerts: openssl 0.10.80, serde_with 3.21.0, h2 0.4.18#2104
erubboli wants to merge 1 commit into
masterfrom
dependabot_openssl_serde_with

Conversation

@erubboli

Copy link
Copy Markdown
Member

Fixes open Dependabot alerts fixable via lockfile updates:

Not addressed (need code changes, not lockfile bumps):

- openssl 0.10.78 -> 0.10.80: RUSTSEC UB in X509Ref::ocsp_responders (high),
  AES key-wrap-with-padding heap overflows (alerts 61, 63, 64)
- serde_with 3.16.1 -> 3.21.0: KeyValueMap panic on malformed input (alert 65)
- h2 0.4.13 -> 0.4.18: RUSTSEC-2026-0258 unbounded empty DATA frames
- cargo-vet: bump exemptions to matching versions, refresh imports.lock
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant