Skip to content

Fix Dependabot alerts: openssl 0.10.80, serde_with 3.21.0, h2 0.4.18 - #2104

Merged
erubboli merged 1 commit into
masterfrom
dependabot_openssl_serde_with
Aug 25, 2026
Merged

Fix Dependabot alerts: openssl 0.10.80, serde_with 3.21.0, h2 0.4.18#2104
erubboli merged 1 commit into
masterfrom
dependabot_openssl_serde_with

Conversation

@erubboli

Copy link
Copy Markdown
Member

Fixes open Dependabot alerts fixable via lockfile updates:

Not addressed (need code changes, not lockfile bumps):

- openssl 0.10.78 -> 0.10.80: RUSTSEC UB in X509Ref::ocsp_responders (high),
  AES key-wrap-with-padding heap overflows (alerts 61, 63, 64)
- serde_with 3.16.1 -> 3.21.0: KeyValueMap panic on malformed input (alert 65)
- h2 0.4.13 -> 0.4.18: RUSTSEC-2026-0258 unbounded empty DATA frames
- cargo-vet: bump exemptions to matching versions, refresh imports.lock
@erubboli
erubboli merged commit 93af22e into master Aug 25, 2026
20 checks passed
@erubboli
erubboli deleted the dependabot_openssl_serde_with branch August 25, 2026 13:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants