This project contains known security vulnerabilities. Find detailed information at the bottom.

Crate v2ray-rust

Dependencies

(54 total, 30 outdated, 1 insecure)

CrateRequiredLatestStatus
 actix-rt^2.82.15.0up to date
 actix-server^2.2.02.9.8up to date
 actix-service^2.02.0.3up to date
 aead^0.50.6.1out of date
 aes^0.8.30.9.3out of date
 aes-gcm^0.100.11.1out of date
 anyhow^1.01.0.104up to date
 async-trait^0.10.1.92up to date
 base64^0.21.20.23.1out of date
 bitvec^11.1.1up to date
 bloomfilter^1.0.93.0.2out of date
 boring^4.2.05.2.0out of date
 boring-sys^4.2.05.2.0out of date
 byte_string^1.01.0.0up to date
 bytes^11.12.1up to date
 chacha20poly1305^0.100.11.0out of date
 cidr-utils^0.5.100.7.1out of date
 clap^44.6.7up to date
 crc32fast^1.3.21.5.2up to date
 env_logger^0.100.11.11out of date
 foreign-types-shared^0.3.10.3.1up to date
 futures-util^0.30.3.34up to date
 generic-array^0.14.71.4.5out of date
 hkdf^0.120.13.0out of date
 hmac^0.120.13.0out of date
 log^0.40.4.34up to date
 md-5^0.10.50.11.0out of date
 prost^0.110.14.4out of date
 protobuf^3.0.13.7.2up to date
 rand^0.80.10.3out of date
 regex^1.7.31.13.1up to date
 serde^1.01.0.229up to date
 sha-1^0.10.10.10.1up to date
 sha2^0.10.60.11.0out of date
 socket2^0.4.70.6.5out of date
 spin^0.9.60.12.3out of date
 tokio^1.261.53.2up to date
 tokio-boring^4.2.05.2.0out of date
 tokio-tungstenite^0.200.30.0out of date
 tokio-util^0.70.7.19up to date
 toml^0.51.1.6+spec-1.1.0out of date
 tonic^0.90.14.6out of date
 uuid^1.31.27.0up to date
 brotli^3.3.49.0.0out of date
 gentian^0.1.80.1.8up to date
 h2 ⚠️^0.3.200.4.19insecure
 http^0.21.5.0out of date
 hyper^0.14.271.11.1out of date
 libc^0.20.2.190up to date
 once_cell^11.21.4up to date
 tower^0.4.130.5.3out of date
 schannel^0.1.210.1.29up to date
 openssl-probe^0.1.50.2.1out of date
 security-framework^2.9.13.7.0out of date

Build dependencies

(2 total, 1 outdated)

CrateRequiredLatestStatus
 protobuf-codegen^3.2.03.7.2up to date
 tonic-build^0.100.14.6out of date

Security Vulnerabilities

h2: h2 unbounded empty DATA frames

RUSTSEC-2026-0258

The h2 crate, used internally by hyper, had a flaw that would accept and queue empty DATA frames without limit. If streams were not actively drained, this could lead to unbounded memory usage, or a panic if the length overflows.

Low severity.

Patched in v0.4.16.