NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
crates.io · #75 most downloaded on crates.io
Rustls is a modern TLS library written in Rust.
Last release 23 days ago
14 Sep 2026
Ships fairly regularly
a new release about every 4 weeks
Rarely documented
notes for 12 of the last 60 stable releases
4 versions withdrawn
withdrawn after publishing
10 years old
116 releases · first in 2016
Nothing published for this version
Nothing published for this version
Bug fix : TLS 1.3 handshake messages incorrectly accepted across encryption level boundaries
Bug fix: TLS 1.3 handshake messages incorrectly accepted across encryption level boundaries
Rustls accepted TLS 1.3 handshake messages sent at the wrong encryption level when they followed a key-changing message in the same record. The handshake transcript is still authenticated, so a network-position attacker cannot use this to alter or complete a handshake; the practical effect is that a peer could send handshake messages that should be encrypted in plaintext without rustls rejecting the connection.
This issue is tracked as GHSA-2mjx-qc3c-rqvc. This issue affects rustls versions 0.23.13 through 0.23.44 inclusive.
Note that this is functionally the same bug as GO-2026-4340.
Full Changelog: v/0.23.44...v/0.23.45
One column per quarter.
Support for post-quantum secure ML-DSA certificates is now enabled by default in the aws-lc-rs crypto provider. ML-DSA certificates are not supported
Support for post-quantum secure ML-DSA certificates is now enabled by default in the aws-lc-rs crypto provider. ML-DSA certificates are not supported in the public web PKI, but they can be used with private certificate hierarchies.
The built-in KeyLogFile implementation now creates files that are restricted to being read only by the owner.
Bug fix : corrected reachable panic in debug mode (or with overflow-checks ) when decrypting a ticket of specific lengths with Rfc5077Ticketer (and th
Bug fix: corrected reachable panic in debug mode (or with overflow-checks) when decrypting a ticket of specific lengths with Rfc5077Ticketer (and therefore rustls::crypto::aws_lc_rs::Ticketer). This happens pre-authentication.
This is not used in the default configuration, but using stateless resumption is common and this affects the aws-lc-rs provider. The ticketer associated with the ring provider is not affected.
Bug fix: A QUIC client using a CryptoProvider that mixes QUIC-capable and -incapable TLS1.3 suites can panic if the server chooses the QUIC-incapable suite.
Bug fix: A QUIC client would incorrectly accept a TLS1.2 server hello. A full handshake would require a trusted server that talks TLS1.2 in QUIC.
Full Changelog: v/0.23.42...v/0.23.43
Implemented support for "TLS Ticket Requests" ( RFC 9149 )
ClientConfig.send_ticket_request configuration field was added to allow specifying TicketRequest parameters for requesting a specific number of TLS 1.3 session tickets from the server. Defaults to None, which skips sending the client extension and preserves current behavior.ServerConfig.max_tls13_tickets configuration field was added to allow setting an upper bound on the number of TLS 1.3 tickets sent in response to a client's request. Defaults to 0, which ignores the client's ticket requests extension and preserves current behavior.Update read_buf API to match current nightly by @djc in #3102
ECH: correct implementation of RFC-recommended padding scheme for SNI names in the inner client hello.
ServerConfig::require_ems based on provider's FIPS status. Prior to this change, the default followed the fips crate feature, which was less helpful for users of external FIPS-approved providers.Full Changelog: v/0.23.39...v/0.23.40
Adapts to updated nightly for the non-default read_buf feature.
Adapts to updated nightly for the non-default read_buf feature.
Full Changelog: v/0.23.38...v/0.23.39
Backport client: allow skipping selected ALPN validation by @TaeHagen in #3020
Adds support for ML-KEM-1024 key exchange.
Adds support for ML-KEM-1024 key exchange.
Full Changelog: v/0.23.36...v/0.23.37
Fix #2825 by allowing P256+SHA512 and P384-SHA512 signatures in certificate chains.
Fix #2825 by allowing P256+SHA512 and P384-SHA512 signatures in certificate chains.
Full Changelog: v/0.23.35...v/0.23.36
There was a regression in 0.23.23 and later where an empty value passed in ConfigBuilder::with_single_cert_with_ocsp() resulted in sending an empty OC
There was a regression in 0.23.23 and later where an empty value passed in ConfigBuilder::with_single_cert_with_ocsp() resulted in sending an empty OCSP value (instead of not sending anything). Thanks to @vuongDang for reporting and fixing.
Fix docs.rs build after doc_auto_cfg stabilization.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →