Update rustls to 0.23.45 for RUSTSEC-2026-0285

rustls 0.23.43 accepted TLS 1.3 handshake messages sent at the wrong
encryption level when they followed a key-changing message in the same
record, where RFC 8446 requires the connection to be terminated. The
transcript is still authenticated, so a handshake cannot be altered, but
a peer could send in plaintext what should be encrypted. It reaches the
agent through tonic -> tokio-rustls, on its mTLS gRPC link to ingest.
Fixed in 0.23.45, inside the existing range, so only the lockfile moves.

The advisory was published after main last passed, so the agent's
cargo-deny advisories job failed on every open PR, including ones that
never touched Rust.

Also drops the RUSTSEC-2025-0134 ignore from agent/deny.toml. Its own
reason said to delete it once tonic stopped pulling in rustls-pemfile;
tonic 0.14 no longer does, and cargo-deny warned the advisory was not
encountered.

Signed-off-by: John Coffey <[email protected]>
This commit is contained in:
2026-09-15 14:50:40 -07:00
parent 44398ea30d
commit cdb58604f0
2 changed files with 2 additions and 18 deletions
+2 -2
View File
@@ -823,9 +823,9 @@ dependencies = [
[[package]]
name = "rustls"
version = "0.23.43"
version = "0.23.45"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "0283386ce02abc0151e1761d08802dfe86c173b0b494af5cbc086574e453da06"
checksum = "0d41d731c7d2f962d1ccc364cec258de3c0e93b38c2fb3ba97ac74513048d634"
dependencies = [
"log",
"once_cell",