Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update h2 #4551

Closed
irevoire opened this issue Apr 4, 2024 · 1 comment
Closed

Update h2 #4551

irevoire opened this issue Apr 4, 2024 · 1 comment
Labels
CPU/RAM usage security Address a security vulnerability v1.7.5 PRs/issues solved in v1.7.5
Milestone

Comments

@irevoire
Copy link
Member

irevoire commented Apr 4, 2024

We're affected by the issue described here: https://seanmonstar.com/blog/hyper-http2-continuation-flood/

A malicious actor could slow down our requests by pushing a lot of tasks into tokio and making Meilisearch slower.
The fix already landed into h2. We simply need to update it

@irevoire irevoire added this to the v1.7.5 milestone Apr 4, 2024
@irevoire irevoire mentioned this issue Apr 4, 2024
meili-bors bot added a commit that referenced this issue Apr 4, 2024
4553: update h2 r=dureuill a=irevoire

# Pull Request

## Related issue
Fixes #4551


4554: Update version for the next release (v1.7.5) in Cargo.toml r=irevoire a=meili-bot

⚠️ This PR is automatically generated. Check the new version is the expected one and Cargo.lock has been updated before merging.

Co-authored-by: Tamo <tamo@meilisearch.com>
Co-authored-by: irevoire <irevoire@users.noreply.github.com>
@curquiza curquiza added the security Address a security vulnerability label Apr 4, 2024
meili-bors bot added a commit that referenced this issue Apr 4, 2024
4553: update h2 r=curquiza a=irevoire

# Pull Request

## Related issue
Fixes #4551


Co-authored-by: Tamo <tamo@meilisearch.com>
@curquiza
Copy link
Member

curquiza commented Apr 5, 2024

Closed by #4553

@curquiza curquiza closed this as completed Apr 5, 2024
@meili-bot meili-bot added the v1.7.5 PRs/issues solved in v1.7.5 label Apr 10, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
CPU/RAM usage security Address a security vulnerability v1.7.5 PRs/issues solved in v1.7.5
Projects
None yet
Development

No branches or pull requests

3 participants