Skip to content

fix(deps): bump h2 to 0.4.17 (RUSTSEC-2026-0258) - #667

Open
changshenhan wants to merge 1 commit into
cloudwego:mainfrom
changshenhan:fix/h2-0.4.17-rustsec-2026-0258
Open

fix(deps): bump h2 to 0.4.17 (RUSTSEC-2026-0258)#667
changshenhan wants to merge 1 commit into
cloudwego:mainfrom
changshenhan:fix/h2-0.4.17-rustsec-2026-0258

Conversation

@changshenhan

Copy link
Copy Markdown

@-

h2 < 0.4.16 is vulnerable to unbounded empty DATA frames (CWE-400 DoS).
Volo-grpc pulls h2 0.4.12 via hyper 1.8.1; bumping to 0.4.17 closes the advisory.

Verified: cargo check --workspace passes (only Cargo.lock changed, +10/-10).
@CLAassistant

CLAassistant commented Aug 20, 2026

Copy link
Copy Markdown

CLA assistant check
All committers have signed the CLA.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants