From df358f69eaa76224cb18bcfd9f4d005a666bc04b Mon Sep 17 00:00:00 2001 From: Johnathan Corgan Date: Mon, 28 Sep 2026 15:31:24 +0000 Subject: [PATCH] Update rustls to 0.23.45 for RUSTSEC-2026-0285 rustls 0.23.43 accepted TLS 1.3 handshake messages across encryption level boundaries. It is the TLS client behind the Nostr relay connections, so every default build reached it. The update is a lockfile change within the version range the dependencies already allow, and the changelog records it under Security. --- CHANGELOG.md | 8 ++++++++ Cargo.lock | 4 ++-- 2 files changed, 10 insertions(+), 2 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 51a669c7..d0ae074f 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -546,6 +546,14 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 request, since that names an event the routing key signed itself. The discovery and traversal design documents describe the new behaviour. +#### Dependencies + +- The lockfile moves `rustls` from 0.23.43 to 0.23.45, for RUSTSEC-2026-0285: + 0.23.43 accepted TLS 1.3 handshake messages across encryption-level + boundaries. It is the TLS client the Nostr relay connections use, so every + default build reached it. The update is within the version range the + dependencies already allowed. + ## [0.5.1] - 2026-09-06 ### Fixed diff --git a/Cargo.lock b/Cargo.lock index 58705dab..823530d1 100644 --- a/Cargo.lock +++ b/Cargo.lock @@ -2960,9 +2960,9 @@ dependencies = [ [[package]] name = "rustls" -version = "0.23.43" +version = "0.23.45" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "0283386ce02abc0151e1761d08802dfe86c173b0b494af5cbc086574e453da06" +checksum = "0d41d731c7d2f962d1ccc364cec258de3c0e93b38c2fb3ba97ac74513048d634" dependencies = [ "once_cell", "ring",