NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
crates.io · #70 most downloaded on crates.io
A protective and efficient HTTP library for all.
Last release today
06 Oct 2026
Ships fairly regularly
a new release about every 2 months
Most releases are documented
notes for 39 of the last 60 stable releases
3 versions withdrawn
withdrawn after publishing
12 years old
253 releases · first in 2014
http1: add max_header_size limit for server and client ( #4183 ) ( d1cd14ef , closes #3832 )
OriginalHeaderOrder doctest by @cratelyn in #4188futures-channel from http1 feature by @0x676e67 in #4185Full Changelog: v1.11.1...v1.12.0
One column per quarter.
detect TE: trailers caselessly and with other values
\n\r\n as a head terminator in the partial-read fast path (#4147) (3534d75c, closes #4145)& and remove allow for lint ref_patterns by @logan-bobo in #4141continue and remove needless_continue allow by @MsfPablo in #4157Full Changelog: v1.11.0...v1.11.1
\n\r\n as a head terminator in the partial-read fast path (#4147) (3534d75c, closes #4145)Upgraded writes without send capacity (#4102) (aecf5abf)ReadBufCursor::initialized_unfilled() method (#4115) (ccc1e850)rt: add ReadBufCursor::initialized_unfilled() method
Upgraded writes without send capacity (#4102) (aecf5abf)cast_lossless lint by @josetorrs in #4087empty_structs_with_brackets lint by @josetorrs in #4088explicit_iter_loop lint by @josetorrs in #4089manual_assert_eq lint by @josetorrs in #4090unnecessary_semicolon lint by @josetorrs in #4103uninlined_format_args lint by @josetorrs in #4104semicolon_if_nothing_returned lint by @MonkieeBoi in #4106 single_match_else lint by @yunz-dev in #4105default_trait_access lint by @nakaryo716 in #4111Upgraded writes without send capacity by @seanmonstar in #4102question_mark lint by @josetorrs in #4116decimal_literal_representation lint by @josetorrs in #4117fix(http1): fix busy loop when peer half-closes and open body by @seanmonstar in #4086
Full Changelog: v1.10.0...v1.10.1
add reset_stream_duration() client option ( #4068 ) ( 156a6f6a , closes #2599 )
NO_ERROR from early response by @ulyssa in #3998header_table_size method to server builder by @ArniDagur in #4062Full Changelog: v1.9.0...v1.10.0
Run cargo-audit in CI to check for known vulnerabilities in dependencies. by @f0rki in #3246
put_slice() by @coryan in #3986max_local_error_reset_streams option by @ffuugoo in #4021http1: fix consuming extra CPU from previous change
Full Changelog: v1.8.0...v1.8.1
Timer::now() method to allow overriding the instant returned (#3965) (5509ebe6)The HTTP/2 client connection no longer allows an executor that can not spawn itself.
This was an oversight originally. The client connection will now include spawning
a future that keeps a copy of the executor to spawn other futures. Thus, if it is
!Send, it needs to spawn !Send futures. The likelihood of executors that match
the previously allowed behavior should be very remote.
There is also technically a semver break in here, which is that the
Http2ClientConnExec trait no longer dyn-compatible, because it now expects to
be Clone. This should not break usage of the conn builder, because it already
separately had E: Clone bounds. If someone were using dyn Http2ClientConnExec,
that will break. However, there is no purpose for doing so, and it is not usable
otherwise, since the trait only exists to propagate bounds into hyper. Thus, the
breakage should not affect anyone.
(58e0e7dc)
Error::is_shutdown() (#3863) (b8affd8a, closes #2745)allow_multiple_spaces_in_request_line_delimiters http1 builder method (#3929) (9749184f)ext::on_informational() callback extension (#3818) (8ce1fcfa, closes #2565)http1::Builder::ignore_invalid_headers(bool) option (#3824) (3817a79b)http2::Builder::max_local_error_reset_streams() now takes &mut self and returns &mut Self. In practice, this shouldn't break almost anyone. It was the wrong receiver and return types.
(e981a91e)rt: add Timer::now() method to allow overriding the instant returned
While technically breaking, it's assumed you will not need to do anything or be affected.
The HTTP/2 client connection no longer allows an executor
that can not spawn itself.
This was an oversight originally. The client connection will now include spawning
a future that keeps a copy of the executor to spawn other futures. Thus, if it is
!Send, it needs to spawn !Send futures. The likelihood of executors that match
the previously allowed behavior should be very remote.
There is also technically a semver break in here, which is that the
Http2ClientConnExec trait no longer dyn-compatible, because it now expects to
be Clone. This should not break usage of the conn builder, because it already
separately had E: Clone bounds. If someone were using dyn Http2ClientConnExec,
that will break. However, there is no purpose for doing so, and it is not usable
otherwise, since the trait only exists to propagate bounds into hyper. Thus, the
breakage should not affect anyone.
(58e0e7dc)
http1::Builder by @Will-Low in #3938docs(SECURITY): update policy to use GSA drafts when reporting vulnerabilities by @seanmonstar in #3894
Error::is_shutdown() (#3863) (b8affd8a, closes #2745)allow_multiple_spaces_in_request_line_delimiters http1 builder method (#3929) (9749184f)HttpService documentation by @cratelyn in #3869TrySendError::message() method by @cratelyn in #3884TrySendError::error() method by @cratelyn in #3885Full Changelog: v1.6.0...v1.7.0
ext: add ext::on_informational() callback extension ( #3818 ) ( 8ce1fcfa , closes #2565 )
ext::on_informational() callback extension (#3818) (8ce1fcfa, closes #2565)http1::Builder::ignore_invalid_headers(bool) option (#3824) (3817a79b)http2::Builder::max_local_error_reset_streams() now takes &mut self and returns &mut Self. In practice, this shouldn't break almost anyone. It was the wrong receiver and return types.Full Changelog: v1.5.2...v1.6.0
fix intermitent panic parsing partial headers ( #3812 ) ( a131111f , closes #3811 )
Full Changelog: v1.5.1...v1.5.2
pass proper value to h2 max_local_error_reset_streams
Nothing published for this version
http1: reject final chunked if missing 0
Nothing published for this version
The returned lifetime from Sleep::downcast_mut_pin() is no longer 'static. This shouldn't affect most usage. This sort of breaking change is needed be…
'static from connection IO trait bounds (#3595) (0013bdda)Sleep::downcast_mut_pin() no longer extend lifetime (7206fe30, closes #3556)max_headers(num) to client and server (#3523) (b1142448)Sleep::downcast_mut_pin()
is no longer 'static. This shouldn't affect most usage. This sort of
breaking change is needed because it is wrong.(7206fe30)
Nothing published for this version
Nothing published for this version
Nothing published for this version
This release "fixes" or adds a few things that should have been in 1.0.0, but were forgotten. Thus, it includes additions that would normally be a sem
This release "fixes" or adds a few things that should have been in 1.0.0, but were forgotten. Thus, it includes additions that would normally be a semver-minor release, but because it is so close to 1.0.0, it is released as a patch version.
Be sure to check out the upgrading guide.
hyper_executor::poll_next (#3370) (0c7d03ef, closes #3369)!Send IO with HTTP/1 client (#3371) (cf87eda8, closes #3363)Http2ClientConnExec and Http2ServerConnExec (52b27faa)http1 header_read_timeout to 30 seconds (8bf26d1e)http 1.0.(899e92a5)
ExecutorClient is renamed to
Http2ClientConnExec, and Http2ConnExec is renamed to
Http2ServerConnExec.(52b27faa)
If you use client HTTP/1 upgrades, you must call
Connection::with_upgrades() to still work the same.
(cf87eda8)
HTTP/2 server builder now has a default max concurrent streams. This is a behavior change. Consider setting your own maximum. (dd638b5b)
Do not build any logic depending on the exact types of
an Error::source(). They are only for debugging.
(502a6450)
The format no longer prints the error chain. Be sure to check if you are logging errors directly.
The Error::message() method is removed, it is no longer needed.
The Error::into_cause() method is removed.
(50f123af)
The ReasonPhrase::from_bytes_unchecked() method is
gone. Use from_static() or TryFrom to construct one.
(4021c57b)
Nothing published for this version
http1 server graceful shutdown fix
hyper::rt::{Read, Write} instead of
tokio::io traits. You can grab a helper type from hyper-util to wrap Tokio types, or implement the traits yourself,
if it's a custom type.
(f9f65b7a)client::conn::http2 types now use another generic for an Executor.
Code that names Connection needs to include the additional generic parameter.
(d977f209)(d894439e)
server: prevent sending 100-continue if user drops request body
client: send an error back to client when dispatch misbehaves () (75aac9f4, closes #2649)
trim obs-folded headers when unfolding
stream cargo feature (#2896) (ce72f734, closes #2855)Service trait (#2920) (fee7d361, closes #2853)The polling functions of the Body trait have been
redesigned.
The free functions hyper::body::to_bytes and aggregate have been
removed. Similar functionality is on
http_body_util::BodyExt::collect.
(0888623d)
Either choose a version-specific Connection type, or
look for the auto-version type in hyper-util.
(0766d3f7)
Pick a version-specific connection, or use the combined
one in hyper-util.
(8ae73cac)
Change any manual impl tower::Service to implement hyper::service::Service instead. The poll_ready method has been removed.
(fee7d361)
The trait has been renamed. (031454e5)
A channel body will be available in hyper-util.
(d963e6a9)
Use the types from http-body-util.
(9e8fc8fc)
Use connect from hyper-util.
(5e206883)
A pooling client is in the hyper-util crate. (bb3af17c)
Tower Service utilities will exist in hyper-util.
(889fa2d8)
server: add Builder::max_pending_accept_reset_streams(num) option
Builder::max_pending_accept_reset_streams(num) option (a24f0c0)Full Changelog: v0.14.31...v0.14.32
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
http1: fix preserving header case without enabling ffi
hyper_clientconn_options_new no longer sets the http1_preserve_header_case connection option by default.
Users should now call hyper_clientconn_options_set_preserve_header_case if they desire that functionality. (78de8914)ffi: don't build C libraries by default
client: avoid panics in uses of Instant
http1: return 414 when URI contains more than 65534 characters (#2706) (5f938fff, closes #2701)
client: cancel blocking DNS lookup if GaiFuture is dropped (174b553d
make ResponseFuture implement Sync
client: don't reuse a connection while still flushing
ffi: on_informational callback had no headers
client: retry when pool checkout returns closed HTTP2 connection
reject content-lengths that have a plus sign prefix
http1: reduce memory used with flatten write strategy
client: allow to config http2 max concurrent reset streams
http1: http1_title_case_headers should move Builder
client: add option to allow misplaced spaces in HTTP/1 responses
client: omit default port from automatic Host headers
build: Fix compile error when only http1 feature was enabled.
http1 feature was enabled.client: HTTP/1 client "Transfer-Encoding" repair code would panic (#2410) (2c8121f1, closes #2409)
client: expose connect types without proto feature
client: log socket option errors instead of returning error (#2361) (dad5c879, closes #2359)
server code an optional feature (#2334) (bdb5e5d6)Body to a new API (#2337) (121c3313, closes #2086)hyper depends on tokio v1 and bytes v1.
Custom resolvers used with HttpConnector must change
to resolving to an iterator of SocketAddrs instead of IpAddrs.
(b4e24332)
hyper no longer emits log records automatically.
If you need hyper to integrate with a log logger (as opposed to tracing),
you can add tracing = { version = "0.1", features = ["log"] } to activate them.
(db32e105)
Removed http1_writev methods from client::Builder,
client::conn::Builder, server::Builder, and server::conn::Builder.
Vectored writes are now enabled based on whether the AsyncWrite
implementation in use supports them, rather than though adaptive
detection. To explicitly disable vectored writes, users may wrap the IO
in a newtype that implements AsyncRead and AsyncWrite and returns
false from its AsyncWrite::is_write_vectored method.
(d6aadb83)
The method Body::on_upgrade() is gone. It is
essentially replaced with hyper::upgrade::on(msg).
(121c3313)
All optional features have been disabled by default. (ed2b22a7)
The HTTP server code is now an optional feature. To
enable the server, add features = ["server"] to the dependency in
your Cargo.toml.
(bdb5e5d6)
The HTTP client of hyper is now an optional feature. To
enable the client, add features = ["client"] to the dependency in
your Cargo.toml.
(4e55583d)
This puts all HTTP/1 methods and support behind an
http1 cargo feature, which will not be enabled by default. To use
HTTP/1, add features = ["http1"] to the hyper dependency in your
Cargo.toml.
(2a19ab74)
http2 cargo feature, which will not be enabled by default. To use
HTTP/2, add features = ["http2"] to the hyper dependency in your
Cargo.toml.(b819b428)
Nothing published for this version
Nothing published for this version
client: fix panic when addrs in ConnectingTcpRemote is empty (#2292) (01103da5, closes #2291)
Your coding agent can read these notes before it upgrades. Set up the MCP server →