nervosnetwork / nervosnetwork/ckb
RUSTSEC-2026-0258: h2 unbounded empty DATA frames
- Dominant language
- Rust
- Stars
- 1.2k
- Forks
- 266
- Avg merge
- 10d 5h
- Merged PRs (30d)
- 4
Description
> h2 unbounded empty DATA frames
| Details | |
| ------------------- | ---------------------------------------------- |
| Package | `h2` |
| Version | `0.4.13` |
| URL | [https://github.com/hyperium/hyper/security/advisories/GHSA-q83h-524g-xf6h](https://github.com/hyperium/hyper/security/advisories/GHSA-q83h-524g-xf6h) |
| Date | 2026-08-17 |
| Patched versions | `>=0.4.16` |
The h2 crate, used internally by hyper, had a flaw that would accept and queue empty DATA frames without limit.
If streams were not actively drained, this could lead to unbounded memory usage, or a panic if the length overflows.
Low severity.
Patched in v0.4.16.
See [advisory page](https://rustsec.org/advisories/RUSTSEC-2026-0258.html) for additional details.
Contributor guide
Research direction
Search the Cargo manifests and lockfile for the h2 dependency at version 0.4.13. Update it to the patched 0.4.16 or later, then run the relevant Cargo tests and dependency checks; done means the repository no longer resolves the vulnerable version.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- rust
- Domain
- security
- Issue type
- Bug
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Active
- Clarity
- Mostly clear
- Newbie friendliness
- 74/100