VDB
Sign up
MEDIUM5.3

RUSTSEC-2026-0285

TLS 1.3 handshake messages incorrectly accepted across encryption level boundaries

Details

Rustls accepted TLS 1.3 handshake messages sent at the wrong encryption level when they followed a key-changing message in the same record. For example, a plaintext `EncryptedExtensions` message packed into the same record as the `ServerHello` was accepted.

RFC 8446 section 5.1 requires that handshake messages do not span key changes, and that implementations terminate the connection with an "unexpected_message" alert if they do.

The handshake transcript is still authenticated, so a network-position attacker cannot use this to alter or complete a handshake; the practical effect is that a peer could send handshake messages that should be encrypted in plaintext without rustls rejecting the connection.

This is functionally the same bug as Go's [GO-2026-4340](https://pkg.go.dev/vuln/GO-2026-4340) (CVE-2025-61730).

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/rustls
Introduced in: 0.23.13Fixed in: 0.23.45

Upgrade rustls to 0.23.45 or newer (ecosystem crates.io).

References