hyperledger-firefly / hyperledger-firefly/cardano

RUSTSEC-2026-0258: h2 unbounded empty DATA frames

Open Beginner friendly
#89 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Rust
Stars
6
Forks
4
PR merge metrics
No merged PRs in 30d

Description

> h2 unbounded empty DATA frames

| Details | |
| ------------------- | ---------------------------------------------- |
| Package | `h2` |
| Version | `0.4.15` |
| URL | [https://github.com/hyperium/hyper/security/advisories/GHSA-q83h-524g-xf6h](https://github.com/hyperium/hyper/security/advisories/GHSA-q83h-524g-xf6h) |
| Date | 2026-08-17 |
| Patched versions | `>=0.4.16` |

The h2 crate, used internally by hyper, had a flaw that would accept and queue empty DATA frames without limit.
If streams were not actively drained, this could lead to unbounded memory usage, or a panic if the length overflows.

Low severity.

Patched in v0.4.16.

See [advisory page](https://rustsec.org/advisories/RUSTSEC-2026-0258.html) for additional details.

Contributor guide

No contributing guide indexed for this repository

Research direction

No file or test is named in the issue. Start by locating the Rust dependency declarations for h2 or hyper, then verify how the repository resolves the affected version; done means the dependency uses h2 0.4.16 or newer and the existing test suite passes.

Written by the indexing model from the issue text.

Assessment

Tech stack
rust
Domain
security
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
67/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.