NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
crates.io · #377 most downloaded on crates.io
Lightweight stream-based WebSocket implementation
Last release 2 months ago
11 Jul 2026
Ships on a steady schedule
a new release about every 3 months
Some releases are documented
notes for 25 of 50 stable releases
Nothing withdrawn
no release was ever pulled
10 years old
50 releases · first in 2017
Reject non-compliant clients (incorrect Sec-WebSocket-Key length/format) on the server side.
Sec-WebSocket-Key length/format) on the server side.rand and sha dependencies and raise MSRV to 1.85.Update MSRV to 1.71 due to syn (the dependency of thiserror) requiring it.
1.71 due to syn (the dependency of thiserror) requiring it.HeaderValue).One column per quarter.
Reduce Error size 136 -> 32 by boxing internals of Error::Http, Error::WriteBufferFull, ProtocolError::InvalidHeader, TlsError::Native, TlsError::Rust
Error size 136 -> 32 by boxing internals of Error::Http, Error::WriteBufferFull,
ProtocolError::InvalidHeader, TlsError::Native, TlsError::Rustls.socket to 0.6.0).into_inner() to the WebSocket, so that the user can extract the underlying stream.tungstenite is built with -Zfmt-debug=none.Fix large message read performance by enforcing max read_buffer_size read chunks.
read_buffer_size read chunks.Hash implementation consistent for Utf8Bytes payloads.Add WebSocketConfig::read_buffer_size docs explaining performance/memory tradeoff.
WebSocketConfig::read_buffer_size docs explaining performance/memory tradeoff.Fix/revert unsoundness that could lead to UB with dodgy Read stream implementations.
Read stream implementations.Simplify Message to use Bytes payload directly with simpler Utf8Bytes for text.
Message to use Bytes payload directly with simpler Utf8Bytes for text.CloseFrame to use Utf8Bytes for reason.Bytes.Remove deprecated WebSocketConfig::max_send_queue.
Payload type for Message that allows sending messages with a payload that can be cheaply cloned (Bytes).
Long standing issue solved!WebSocketConfig::read_buffer_size default 128 KiB. This improves high load read performance.
Note: This default increases memory usage compared to previous versions particularly for users expecting a high number of connections. Configure 4-8 KiB to get a similar memory usage to 0.24.WebSocketConfig non-exhaustive & add builder style construction fns.WebSocketConfig::max_send_queue.Sec-WebSocket-Protocol header.thiserror to 2.Raised MSRV to 1.63 to match tokio-tungstenite.
tokio-tungstenite.Disable default features for rustls giving the user more flexibility.
rustls giving the user more flexibility.Add a builder for convenient headers and subprotocols construction.
url optional.rustls dependency.Fix read-predominant auto pong responses not flushing when hitting WouldBlock errors.
FrameHeader::format write correctness.rustls to 0.22.webpki-roots to 0.26.rustls-native-certs to 0.7.http to 1.0.0.- Fixes CVE-2023-43669.
Add WebSocket::read, write, send, flush. Deprecate read_message, write_message, write_pending.
flush. An exception is automatic responses (e.g. pongs)
which will continue to be written and flushed when reading and writing.
This allows writing a batch of messages and flushing once, improving performance.WebSocket::read, write, send, flush. Deprecate read_message, write_message, write_pending.FrameSocket::read, write, send, flush. Remove read_frame, write_frame, write_pending.
Note: Previous use of write_frame may be replaced with send.WebSocketContext::read, write, flush. Remove read_message, write_message, write_pending.
Note: Previous use of write_message may be replaced with write + flush.send_queue, replaced with using the frame write buffer to achieve similar results.
WebSocketConfig::max_write_buffer_size. Deprecate max_send_queue.Error::WriteBufferFull. Remove Error::SendQueueFull.
Note: WriteBufferFull returns the message that could not be written as a Message::Frame.WebSocketConfig::write_buffer_size (default 128 KiB). Improves batch message write performance.WebSocketConfig.Exchanging base64 for data-encoding.
base64 for data-encoding.Make handshake dependencies optional with a new handshake feature (now a default one!).
handshake feature (now a default one!).Respect the case-sentitivity of the "Origin" header to keep compatibility with the older servers that use case-sensitive comparison.
Fix panic when invalid manually constructed http::Request is passed to tungstenite.
http::Request is passed to tungstenite.1.56 due to some other crates that rely on us not being quite ready for 1.58.Specify the minimum required Rust version.
Update of dependencies (primarily sha1).
sha1).http::Request "as is" to tungstenite-rs, letting the library to check the correctness of the request and specifying their own headers (including its own key if necessary). No changes for those ones who used the client in a normal way by connecting using a URL/URI (most common use-case).Update of dependencies (primarily rustls, webpki-roots, rustls-native-certs).
rustls, webpki-roots, rustls-native-certs).ReadBuffer implementation uses heap instead of stack to store the buffer. This should solve issues with possible stack overflows in some scenarios (see #241 for more context).Allow selecting the method of loading root certificates if rustls is used as TLS implementation.
rustls is used as TLS implementation.
rustls-tls-native-roots and rustls-tls-webpki-roots have been added
that activate the respective method to load certificates.rustls-tls flag was removed to raise awareness of this change. Otherwise, compilation
would have continue to work and potential errors (due to different or missing certificates)
only occurred at runtime.Use rustls-native-certs instead of webpki-root when rustls-tls feature is enabled.
rustls-native-certs instead of webpki-root when rustls-tls feature is enabled.native-tls as a default feature (see #202 for more details).input_buffer).Error enum that can't be triggered anymore with the new buffer implementation.Add CapacityError, UrlError, and ProtocolError types to represent the different types of capacity, URL, and protocol errors respectively.
CapacityError, UrlError, and ProtocolError types to represent the different types of capacity, URL, and protocol errors respectively.Error::Capacity, Error::Url, and Error::Protocol to hold the above errors types instead of string error messages.handshake::derive_accept_key to facilitate external handshakes.rustls as TLS backend. The previous tls feature flag is now removed in favor
of native-tls and rustls-tls, which allows to pick the TLS backend. The error API surface had
to be changed to support the new error types coming from rustls related crates.Add facilities to allow clients to follow HTTP 3XX redirects.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →