This project might be open to known security vulnerabilities , which can be prevented by tightening the version range of affected dependencies. Find detailed information at the bottom .
Crate fuzz Dependencies (1 total, all up-to-date)
Crate mtu Dependencies (1 total, 1 outdated)
Crate Required Latest Status windows >=0.58, <0.600.62.2out of date
Build dependencies (3 total, 1 outdated)
Crate neqo-bin Dependencies (4 total, 1 possibly insecure)
Dev dependencies (2 total, 1 outdated, 1 possibly insecure)
Crate Required Latest Status criterion ^0.60.7.0out of date tokio ⚠️ ^11.48.0maybe insecure
Crate neqo-common Dependencies (1 total, 1 outdated)
Crate Required Latest Status env_logger ^0.100.11.8out of date
Dev dependencies (1 total, 1 outdated)
Crate Required Latest Status criterion ^0.60.7.0out of date
Crate neqo-crypto Build dependencies (6 total, 2 outdated)
Crate neqo-http3 Dependencies (1 total, all up-to-date)
Crate Required Latest Status sfv ^0.140.14.0up to date
Dev dependencies (1 total, 1 outdated)
Crate Required Latest Status criterion ^0.60.7.0out of date
Crate neqo-qpack No external dependencies! 🙌
Crate neqo-transport Dependencies (2 total, all up-to-date)
Crate Required Latest Status indexmap ^2.22.12.0up to date smallvec ^1.131.15.1up to date
Dev dependencies (1 total, 1 outdated)
Crate Required Latest Status criterion ^0.60.7.0out of date
Crate neqo-udp Build dependencies (1 total, all up-to-date)
Crate Required Latest Status cfg_aliases ^0.20.2.1up to date
Crate test-fixture No external dependencies! 🙌
Security Vulnerabilities tokio: reject_remote_clients Configuration corruptionRUSTSEC-2023-0001
On Windows, configuring a named pipe server with pipe_mode will force ServerOptions ::reject_remote_clients as false.
This drops any intended explicit configuration for the reject_remote_clients that may have been set as true previously.
The default setting of reject_remote_clients is normally true meaning the default is also overridden as false.
Workarounds
Ensure that pipe_mode is set first after initializing a ServerOptions . For example:
let mut opts = ServerOptions::new();
opts.pipe_mode(PipeMode::Message);
opts.reject_remote_clients(true);
Patched
>=1.18.4, <1.19.0
>=1.20.3, <1.21.0
>=1.23.1