tauri-apps / tauri-apps/plugins-workspace

RUSTSEC-2026-0258: h2 unbounded empty DATA frames

Open Beginner friendly
#3,543 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Rust
Stars
1.8k
Forks
602
Avg merge
4d 14h
Merged PRs (30d)
9

Description

> h2 unbounded empty DATA frames

| Details | |
| ------------------- | ---------------------------------------------- |
| Package | `h2` |
| Version | `0.4.9` |
| URL | [https://github.com/hyperium/hyper/security/advisories/GHSA-q83h-524g-xf6h](https://github.com/hyperium/hyper/security/advisories/GHSA-q83h-524g-xf6h) |
| Date | 2026-08-17 |
| Patched versions | `>=0.4.16` |

The h2 crate, used internally by hyper, had a flaw that would accept and queue empty DATA frames without limit.
If streams were not actively drained, this could lead to unbounded memory usage, or a panic if the length overflows.

Low severity.

Patched in v0.4.16.

See [advisory page](https://rustsec.org/advisories/RUSTSEC-2026-0258.html) for additional details.

Contributor guide

Open the contributing guide

Research direction

The issue concerns the h2 crate used internally by hyper; start by tracing how that dependency is resolved in the workspace. Done means h2 resolves to version 0.4.16 or later, with the existing project validation passing; no specific file or test is named.

Written by the indexing model from the issue text.

Assessment

Tech stack
rust
Domain
security
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
72/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.