Skip to content

Update bytes 1.11.1 due to RUSTSEC-2026-0007#375

Open
dancewithheart wants to merge 1 commit into
tlepoint:mainfrom
dancewithheart:update-bytes
Open

Update bytes 1.11.1 due to RUSTSEC-2026-0007#375
dancewithheart wants to merge 1 commit into
tlepoint:mainfrom
dancewithheart:update-bytes

Conversation

@dancewithheart
Copy link
Copy Markdown

Update bytes 1.11.1 due to CVE-2026-25541 ( RUSTSEC-2026-0007 )

Reported by cabal audit:

Crate:     bytes
Version:   1.10.1
Title:     Integer overflow in `BytesMut::reserve`
Date:      2026-02-03
ID:        RUSTSEC-2026-0007
URL:       https://github.com/advisories/GHSA-434x-w66g-qw3r
Solution:  Upgrade to >=1.11.1
Dependency tree:
bytes 1.10.1
└── prost 0.14.3
    ├── prost-types 0.14.3
    │   └── prost-build 0.14.3
    │       ├── fhe-math 0.2.0
    │       │   └── fhe 0.2.0
    │       └── fhe 0.2.0
    ├── prost-build 0.14.3
    ├── fhe-math 0.2.0
    └── fhe 0.2.0

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant