Skip to content

chore(deps): upgrade h2 to 0.4.19 (RUSTSEC-2026-0258) - #2552

Merged
wsp1911 merged 1 commit into
mainfrom
codex/h2-0.4.19-rustsec-2026-0258
Aug 27, 2026
Merged

wsp1911 merged 1 commit into
mainfrom
codex/h2-0.4.19-rustsec-2026-0258

Conversation

@wsp1911

@wsp1911 wsp1911 commented Aug 27, 2026

Copy link
Copy Markdown
Collaborator

Summary

Upgrade the transitive h2 dependency from 0.4.15 to 0.4.19 to address RUSTSEC-2026-0258. Version 0.4.16 is the minimum patched release, while 0.4.19 also includes the follow-up fixes that prevent the new DATA-frame protection from rejecting legitimate small-frame traffic.

Only Cargo.lock changes; no application source or dependency-graph changes are included.

Fixes #2459

Supersedes #2461. Thanks to @1688mengdie for identifying the advisory and preparing the original dependency update.

Type and Areas

Type: dependency

Areas: Rust core dependency

Motivation / Impact

RUSTSEC-2026-0258 affects h2 0.4.15: an HTTP/2 peer can send unbounded empty DATA frames, leading to unbounded memory use or a panic when streams are not actively drained.

Upgrading directly to 0.4.19 closes the advisory while also including the 0.4.17-0.4.19 follow-up corrections for legitimate concurrent and streaming small-frame workloads. There is no direct user-facing change.

Verification

  • cargo check --locked -p bitfun-core — passed.
  • cargo tree --locked -i h2 --depth 1 — resolved h2 v0.4.19 through hyper v1.11.0 and reqwest v0.13.4.
  • git diff --check — passed.
  • Full workspace, runtime HTTP/2, remote scenarios, and UI checks were not run locally; repository CI remains the cross-platform verification source.
  • This is an AI-assisted change.

Reviewer Notes

  • h2 0.4.19 keeps the same 0.4.x compatibility line, Rust 1.63 minimum, dependency list, and Cargo features as 0.4.16.
  • No UI change, screenshots, migration, or persisted-shape compatibility work is applicable.
  • Rollback is the inverse lockfile-only version/checksum change.

Checklist

  • This PR is focused and does not include secrets, temporary prompts, generated scratch files, or unrelated artifacts.
  • Relevant verification is recorded above, or skipped checks are explained.
  • User-facing strings, docs, and locales are updated where applicable. (Not applicable: no user-facing change.)

Upgrade the transitive h2 dependency from 0.4.15 to the latest patched 0.4.x release. This closes RUSTSEC-2026-0258, which allows unbounded empty DATA frames to cause memory exhaustion or a panic, and includes follow-up fixes that avoid rejecting legitimate small-frame traffic.

Only the locked version and checksum change; the dependency graph and application sources are unchanged.

Test: cargo check --locked -p bitfun-core; cargo tree --locked -i h2 --depth 1

AI: lightly tested
@wsp1911
wsp1911 merged commit e07bfac into main Aug 27, 2026
12 checks passed
@GCWing
GCWing deleted the codex/h2-0.4.19-rustsec-2026-0258 branch August 30, 2026 19:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Security]: h2 0.4.15 affected by RUSTSEC-2026-0258

1 participant