Skip to content

fix(deps): bump h2 to fix unbounded empty DATA frames DoS - #92

Closed
SafraNako wants to merge 1 commit into
dfinity:mainfrom
SafraNako:fix/h2-dos-advisory
Closed

SafraNako wants to merge 1 commit into
dfinity:mainfrom
SafraNako:fix/h2-dos-advisory

Conversation

@SafraNako

Copy link
Copy Markdown

What

h2 0.4.15 → 0.4.16: RUSTSEC-2026-0258 — a peer could send unbounded empty HTTP/2 DATA frames to exhaust memory/CPU.

Cargo.toml's range already allows 0.4.16, so this is cargo update -p h2 --precise 0.4.16 only — no manifest or source changes.

Verified locally

cargo test --workspace --bins → 4 tests passed, 0 failed.

🤖 Generated with Claude Code

h2 0.4.15 -> 0.4.16: RUSTSEC-2026-0258, a peer could send unbounded
empty HTTP/2 DATA frames to exhaust memory/CPU. Cargo.toml range
already allows 0.4.16, so this is `cargo update -p h2 --precise
0.4.16` only -- no manifest changes.

Verified locally: `cargo test --workspace --bins` passes (4 tests).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@SafraNako
SafraNako requested a review from a team as a code owner September 11, 2026 21:19
Copilot AI lite review requested due to automatic review settings September 11, 2026 21:19

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot wasn't able to review any files in this pull request.


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@github-actions

Copy link
Copy Markdown

Thank you for contributing! Unfortunately this repository does not accept external contributions yet.

We are working on enabling this by aligning our internal processes and our CI setup to handle external contributions. However this will take some time to set up so in the meantime we unfortunately have to close this Pull Request.

We hope you understand and will come back once we accept external PRs.

— The DFINITY Foundation

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants