Remove RUSTSEC-2026-0258 suppression once actix-http drops h2 0.3

Open
#455 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
2/5
Estimated time
1-3 hours
Newbie friendliness
55/100
Issue type
Bug
Clarity
Mostly clear
Activity status
Quiet
Tech stack
rust
Domain
security, tooling

Research direction

Check the actix-http dependency version and its h2 requirement in the dev-server closure. When h2 0.4 or a patched h2 0.3 release is available, update the affected dependency, remove RUSTSEC-2026-0258 from deny.toml, and run cargo xtask deny to confirm the suppression is no longer needed.

Written by the indexing model from the issue text.

Description

deny.toml currently suppresses RUSTSEC-2026-0258 (h2 0.3 empty DATA frame DoS), which reaches the workspace transitively through actix-http/awc in the dev-server.

# h2 0.3 (transitive dep of actix-http/awc) — low-severity empty DATA frame DoS;
# actix-http 3.13.3 still pins h2 0.3 and that series has no patched release
"RUSTSEC-2026-0258",

At the time it was added, actix-http 3.13.3 still pinned h2 0.3 and that series had no patched release, so there was no upgrade path.

This issue exists so the suppression is re-evaluated rather than left in place indefinitely.

Action

Once actix-http ships a release that depends on h2 >= 0.4 (or the 0.3 series receives a patched release):

  1. Bump the affected dependency.
  2. Remove the RUSTSEC-2026-0258 entry from deny.toml.
  3. Confirm cargo xtask deny passes without it.
Notes
  • Only the dev-server dependency closure is affected. The published renderer packages (Rust crates, Node addon, Python wheels, FFI) do not depend on h2 or actix.
Dominant language
Rust
Stars
90
Forks
23
Avg merge
13h 3m
Merged PRs (30d)
64

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from microsoft/webui

All issues in microsoft/webui

Similar issues

More Rust issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.